Api user permissions to access only one vault

Hi, is it possible for an api user to have granular access so that he can only transfer/view the assets from one vault? How could this be accomplished? Thanks

Would TAP (Transaction Authorization Policy) help me achieve this? in the sandbox, I cannot configure it.

I tried to modify the ‘profile > quorums > Change the TAP’ section enable TAP modification, but an error is thrown: