After thinking about for a while, I still do not get it really.
I have app "Simple Gallery". I can restrict the access to certain folders (using Storage Scopes) for this app after it asks me for permissions. E.g. it loads images only from DCIM/A for example.
Then I have the app e.g. KeepassX, which can open any file in DCIM without asking for permissions. I also can not restrict the access for this app.
This does not make sense to me? My goal is e.g. that I have a KeepassX ".kdbx" file and only KeepassX (and mayby a few necessary system "apps" / root) have access to it.