Skip to content
SkyKeephelp

The demonstration installation

Showing the vault to someone used to cost a full manual setup: create the

compartments, invite the people, rotate every forced password, find some

documents, upload them, and hope the reach came out right — paid again

for every demonstration. One operator command now stands up a complete,

populated, immediately demonstrable vault instead: two compartments named

hr and sales, six accounts, and a public-domain demonstration corpus

split by document category so that each account sees a different slice

of the same vault.

The six accounts are three pairs, and each pair differs in exactly one

thing. Both halves hold the same compartments; one of them may file

documents into them and the other, named with an "_ro" suffix so the

pairing is legible in the sign-in list itself, may only ask. Being able

to read and not to write is a first-class thing to be here rather than a

half-broken account — in a real engagement it is what most people are —

so the demonstration ships those people and lets an audience watch both

halves of a pair work the same compartment side by side. A read-only

account signs in the same way, reaches the same documents, searches,

asks, reads summaries and follows citations exactly as its writing twin

does. The single difference is that the vault refuses to let it file a

document, and refuses without storing any part of one.

Three things make that repeatable, and the same three would be a serious

vulnerability in any real deployment: all six accounts share one email

address, they share one short password, and none of them is asked to

change that password at first sign-in — the single documented exception

to the rule that every provisioned account must replace its admin-known

password before the vault will do anything else for it. So the weakness

is fenced by the vault itself rather than by a warning in a document.

The mode refuses unless the deployment has been explicitly marked for

demonstration use, and is reachable only as an operator command — never

from any page or interface, for any account, including an administrator.

Behind that marker it EMPTIES the vault before it builds: every document,

compartment and account is removed and the demonstration is rebuilt from

nothing, so it is the same vault every time however much anybody clicked

around beforehand. Refusing when the vault was not already empty would

sound safer and would not be: the guarantee would expire the first time

somebody tried an upload. Two things the emptying never touches: the

audit trail and the deployment's own configuration. So everything the

trail already recorded about those documents — who uploaded them, who

read them, what was refused — outlives them. The emptying itself writes

no entry, and the rebuild that follows writes the ordinary ones, because

it goes through the same audited path an operator's own work does.

What is NOT waived is the authentication itself. All six demonstration

accounts are created already enrolled with their second factor turned

off, which is a state any account can put itself into from its own

profile page — so they sign in on the password alone by the ordinary

policy, and a demonstration needs no mailbox at all. Being read-only is

not an authentication difference and buys no lesser footing at the door:

a read-only account signs in on exactly the terms its writing twin does.

The administrator was never put in that state, so it is asked for its

code like anybody else. A demonstration authenticates people exactly as

a real deployment does, because that is part of what it is demonstrating.

Showing it to somebody is its own job, so the vault ships the script for

that too: an ordered list of what to show, each beat with the clicks that

show it and the point it makes, and a set of sample questions that cannot

be answered out of one document. The questions are chosen so their

evidence falls on both sides of the compartment boundary — which is what

makes the same question return different answers to different accounts —

and one of them deliberately does not, so that an audience can see the

difference is about grants rather than about some accounts getting a

worse vault. Each question says how it was checked, and the page says

plainly which of its claims no test holds.

A deployment that never asked to be a demonstration vault

A marker that was set by accident is not a marker

A vault that already holds work nobody demonstrated is emptied firststack

Emptying the vault never erases the record of what happenedstack

One command stands up the demonstration vaultstack

Each slice of the corpus is placed by the account that owns itstack

An account cannot file a document into a compartment it cannot writestack

A read-only account cannot file a document even into its own compartmentstack

A read-only account signs in on the password alone, like its writing twinstack

A read-only account reaches every document its writing twin reachesstack

Each account sees a different slice of the same vaultstack

Asking after a document you cannot reach tells you nothingstack

Running it a second time converges instead of duplicatingstack

The presenter's script is one question asked by three accounts

Every sample question says which documents it needs

One sample question is answered the same way by every account

The page says which of its claims no test holds