PeopleContext / interactive demo
Same company.
Different access.
Explore who can see HR records. Switch identities, move an employee, and revoke HR access. Watch the real permissions change.
Fictional data. Predefined actions. No live AI. No messages sent.
Checking your workspace…
A private workspace
Five people. Four kinds of records.
Start with Alice, Bob’s manager. Your temporary workspace is separate from other visitors and expires automatically.
1 / Choose an identity
Whose view is this?
Everyone sees their own compensation. Managers also see compensation for their reporting chain; HR sees all compensation. Personal details are visible to their owner and HR. Only HR sees notes.
The reporting structure
A small, fictional team
2 / Inspect the visible records
Returned by the server
These tables show the actual query responses. Rows hidden from the selected identity are excluded from each response.
3 / Change the policy
Demo administrator actions
These controls use a separate demo administrator. Selecting an employee above does not grant them permission to make these changes.
Transfer Bob
Move Bob to Carol. Alice and Dana immediately lose access to his compensation; Carol gains access.
Revoke HR access
View as Helen, then remove her HR role. She keeps her own compensation and personal details, but loses access to other compensation and all notes. The demo reuses her original login token.
4 / Try other access paths
Can these restrictions be bypassed?
Try reading policy tables through SQL and compensation through the direct REST API. These paths are blocked for every demo identity, including HR.
Request details
SQL runs against a snapshot containing only the selected account’s authorized rows. The server applies the policy; the browser displays the response.