Databunker Pro: Role Access Token Demo

A root token can read everything. Most services should not. This example shows how to mint a role access token that is scoped down to exactly one slice of your data — and then prove what it can and cannot reach. It covers:

  • Scoping to One App: A billing service that sees billing app data and nothing else
  • Scoping to a Group: The same access, restricted to customers in one region
  • Scoping by File Tag: A KYC reviewer that sees passports but not contracts
  • Cross-User Lookups: Tenant-wide search that still respects the group boundary

Every step runs against a live vault. Denials below are real API responses, not illustrations.

ℹ️ All requests are executed in the sandbox environment (show/hide configuration).

Step 1: Set Up Two Customers

One customer in the EU group, one outside it. Each gets app data and documents.

Step 2: One App, All Users

A billing service that may touch billing app data — for any customer, but nothing else
Try it free — startups get $1,000 in credits

If you're an early-stage startup, we'll give you $1,000 in credits — enough to run Databunker Pro completely free for your first couple of months. Book a short setup call and we'll get you started and apply the discount automatically.

Step 3: Prove the Scope

Connect as the billing service and try to step outside the policy

Step 4: One App, One Group of Users

Add a group to the Resource list and the same access narrows to that group's members

Step 5: A Group of Files, by Tag

A KYC reviewer that sees identity documents — and does not even learn that other documents exist

Step 6: Tagged Files, One Group — Cross-User Lookup

Search every customer's documents at once, with the group boundary still enforced

Step 7: Review What Was Issued

List the policies now defined in this tenant

Next Step

See Databunker Pro in Action

Book a 15-min setup call and we'll get Databunker running for you in minutes. No technical work required on your end.

Book 15-Min Setup Call