ScopeFS
Hand out a key. Not the whole building.
Give your app access to one storage space. Take it back in a second. Your real credentials never move.
IMG hero-key — brass key, shot from above, hard raking light. Real and worn, not a render.
The situation
- You’re holding one key that opens every drawer.
- You’ve been meaning to change it since it was handed to you.
- If something went missing, you wouldn’t know who took it.
Most storage problems are one of these three. You can fix the first two tonight.
The keys are real S3 keys
The same key works with the tools you already run. The only difference is that you can take this one back.
aws s3 cp invoice.pdf s3://invoices/invoice.pdfOne space. Several keys.
Each key is made for one space and does one set of things. The cut pattern comes from what it can do, so a permission level can be read by shape.
read only
Reads that space. Cannot write, cannot delete.
read write
Reads and writes that one space.
taken back
Opens nothing, anywhere, immediately.
The whole-building key still exists. Some people need it — it is a decision here, not a default.