Atlas renders an IR file (a normalized JSON snapshot of an account). The demo uses a built-in sample; load your own three ways:
Click Load IR in the top bar and pick an inventory.ir.json. It stays in your browser — nothing is uploaded or published. A ↺ sample button switches back.
Read-only, and you can prove it. The scanner makes only Describe / List / Get calls — it cannot create, modify, or delete anything in your account, creates no IAM role, and writes a single local JSON file. Open it and read it before you run it; every AWS call is one of those three verbs.
⬇ Download atlas_scan.py then, using your existing AWS credentials:
pip install boto3 python atlas_scan.py --regions us-east-1 -o inventory.ir.json
Load the resulting inventory.ir.json with Load IR above — it stays in your browser, nothing is uploaded.
Open CloudShell (boto3 is preinstalled), upload atlas_scan.py, run python atlas_scan.py -o inventory.ir.json, download the result, then Load IR.
A scan can't see your data center. Add it to the IR as declared input — then test reachability from an on-prem IP:
"onPrem": [{
"id": "onprem-dc1", "name": "HQ",
"cidrs": ["10.100.0.0/16"],
"attachment": "vgw-xxxx", // or tgw-/dxgw- attachment
"advertisedRoutes": ["10.0.0.0/16"],
"verified": false
}]
Click two resources (1st = source, 2nd = destination), or type any IP/CIDR in the source/destination boxes — Atlas resolves it to a resource, a subnet host, your on-prem range, or the internet, then evaluates routes, security groups and NACLs.
Keep the public site on the sample; explore real accounts via Load IR. A topology with internal IPs and open-port findings shouldn't live at a public URL.
Pick a scenario to see Atlas in action, or use the Source / Destination dropdowns on the right to trace any path yourself.
Atlas reads a read-only snapshot of an account into a normalized model, then a reachability engine evaluates whether one resource can open a connection to another — walking every gate a packet would actually cross. The same engine runs in the browser and as a Python CLI; the two are kept in lockstep and checked against each other on every release.
Atlas reasons about network reachability, not identity or application authorization. It does not evaluate IAM policies, S3 bucket or other resource policies, application-layer auth, DNS resolution, or deep stateful firewall rule logic beyond drop rules. It is single-account and single-region per view. Stating this is deliberate — reachability is necessary but not sufficient for access.
Reachability Analyzer is excellent for a single in-VPC ENI-to-ENI path and is billed per analysis. Atlas adds the parts it doesn't cover: on-prem over Direct Connect / VPN, Transit Gateway segmentation, PrivateLink-to-SaaS with endpoint policies, account-wide blast radius and unused-exposure reporting, and a readable path itinerary — running locally with no per-analysis cost. They're complementary: RA to confirm one official path, Atlas to reason across the whole account including the on-prem and SaaS edges.