Shared Links
The Shared Links section is where you configure shared link settings and permissions for content owned by managed users.Allow shared links for
Defines the content type you allow to be shared. Select from:- Folders, files, and hubs (default) - All content in your account use the shared link settings that follow this option.
- Folders only - Folders in your account use the shared link settings that follow. Shared links for files can be created, but the only sharing option for shared links on files is Invited people only, which means files using the shared link are accessible only by invited collaborators in the folder.
- Files only - Files in your account use the shared link settings that follow. Shared links for folders can be created, but the only sharing option for shared links on folders is Invited people only, which means folders using the shared link are accessible only by invited collaborators in the folder.
- Invited people only - Disables shared links for everyone except invited collaborators to the file, folder, or hub.
Definition of company
When selecting the “people in your company” setting, define what “in your company” means. Select from:- Users with email domain (default) - “In your company” is defined as any user with an email address within your company’s domain. (This option shows the domain.)
- Enterprise ID - “In your company” is defined as only managed users in your account.
People who can access shared links
Defines what access options are available for the content types selected above. By default, all options are enabled, meaning that anyone with appropriate permissions can choose, per item, what access permission to grant their content. Select from:- People with the link, people in your company, and people in this folder (default) - Anyone with the link can access. But people can still set a password or expiration date for these links. There is no login required.
- People in your company and people in this folder only - This is available only if an email domain is added to your account. If you create a link with this setting, everyone in your Box account can see the link, and people within the added email domain who are part of an external Business (or higher) level account can also see the link.
- People in this folder or file only - Only people collaborated into the folder can access its content from a shared link. An exception is if a parent folder allows different shared link permissions, in which case the parent folder shared link permissions are inherited.
Default access for shared links
Defines the default access level of newly-created shared links. If you have limited the access options in an earlier setting, your options here are limited accordingly.- People with the link (default) - The content is open to people with the link. File viewers do not have to log in.
- People in your company - Anyone with the link who’s also in your company, or people invited to this file, can access its content.
- People in this folder - Only people collaborating in this folder can access its content.
Shared Link Permission
Defines the allowed and default permissions for file, folder, and Box Notes shared links. For files, folders, and Box Notes, you define both the maximum permission allowed and the default permission when users share links. You can select from the following values for each:- Can view, download, and edit
- Can view and download
- Can view and edit
- Can view only
- View means that link viewers can only preview the item. Download and edit is disabled. Managed users cannot toggle this setting at the folder and file level.
- Download means that link viewers can download the files, folders, and Box Notes. With this option enabled, managed users can toggle the download setting at the folder and file level.
- Edit means that link viewers can edit the linked file, files in the linked folder, or the Box Note. More specifically, editable file sharing links are shared links that grant editing permissions to files stored in Box for people with those links. Your managed users can select the edit option in the sharing modal for a file within Box if you include edit in the maximum permission allowed.
Note:The permission you see on the file/folder list view and the permission from within a Box Note file can be different.This is dependent on the Shared Link Permission setting. The Files permission type is used when on the file/folder list view. The Box Notes permission type is used within Box Note files.For example, if Files has the permission of Can view only and Box Notes has the permission of Can view and edit:
- When on the file/folder list view, selecting Share Link for the Box Note displays Can view only. The option Can edit is not available.
- After clicking into the same Box Note, selecting Share then Get link allows the user to select Can edit.
Custom Shared Links
Custom URLs enable people to customize the URLs for created shared links. This applies to content you want to be readily accessible to large groups of people (externally or internally) using a customized URL that is easy to remember. If you make this link available as people with the link, the linked folder or file is publicly accessible. Custom URLs are appropriate for public-facing materials such as product documentation or marketing materials and are not intended for the secure sharing of sensitive content.Allow custom shared link URLs for links with public access
Select the check box to enable the custom URL feature for open public sharing. Example of a custom link: https://.box.com/v/custom-public-link Clear the check box to block the creation of custom URLs in your enterprise. If you disable this option, you break any existing custom URLs with people with the link permissions. However, if you later re-enable public custom URLs, those same pre-existing links again become valid. This setting does not apply to custom URLs with company and collaborators-only security levels. The default state is cleared.Show your custom domain in shared link URLs
Select the check box to enable your custom domain display in shared link URLs. The default state is selected.Collaborating on Content
This section is where you select the roles/permissions you want to allow folder owners to choose from when collaborating on items and define other collaboration settingsAvailable Roles
Determines which roles can be chosen for collaborators. Roles selected here are available to choose from when setting access levels for collaborators. Each role provides different access levels. The default states are selected for all roles.Default collaboration roles
Determines the default access level across your entire organization for files people share. Select from:- Editor (default)
- Viewer (more secure)
Restrict invites
Determines who can invite collaborators. Select this option so only folder Owners and Co-owners and Admins (including Co-admins and Group Admins) can invite collaborators to a given folder. The default state is cleared.Enable invite links
Determines whether people can use invite links to collaborate. Invite links grant collaborator access to a folder to people who click the link. If these links are disabled, users are still able to invite collaborators through email invites sent securely by Box. Unless accepted, pending collaboration invitations expire after 30 days. The default state is selected.Enable group invites
Determines whether users can invite groups to collaborate in folders. Enabling group invites allows collaborators with editor, co-owner, or owner permissions to invite group collaborators and modify their permissions on those items. The default state is selected.Restrict Ownership Transfer
Determines whether non-admins can transfer ownership of a file or folder to external collaborators and move a file or folder owned by your enterprise to a folder owned by an external account. Select this option to prevent ownership transfer of a file or folder to external collaborators. Admin and co-admins of your account can still transfer ownership to external collaborators. The default state is cleared.Move and copy content to a folder
Determines whether the collaborators can move or copy content to a folder where they have a higher permission level. Admins can prevent or allow collaborators to move or copy content to a folder where they have a higher permission level. If the setting is configured to prevent such actions, an error message is displayed when collaborators attempt to do so. Notes:- Selecting Prevent collaborators from moving or copying content to a folder where they have a higher protection level does not prevent Copy operations being conducted through Box Drive
- Co-admins can also change this setting if they have the following permissions enabled:
- View settings and integrations for your company
- Edit settings and integrations for your company
- Prevent collaborators from moving or copying content to a folder where they have a higher permission level does not apply to Automate workflows. Therefore, moving or copying content into folders through Automate workflow may still result in some users being granted higher permission level. You can mitigate this risk by allowing users to create workflows only with folders where they have Owner/co-owner permission in Box Automate enablement settings.
External collaboration
Determines whether your users can collaborate with any external collaborators (default) or only external collaborators in allowlisted domains. See Limit collaboration to allowlisted domains for details.Canvas
Box Canvas is a visual collaboration and whiteboarding tool that enables teams to collaborate visually using sticky notes, shapes, text input, image uploads, and more.Configure Canvas
Defines who can use Box Canvas. Click Edit Configuration and then select:- Disable for all managed users
- Enable for all managed users (default)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
Watermarking
Watermarking places a semi-transparent overlay of the current viewer’s name and time of access across a document’s contents to deter unauthorized sharing. When your Box users choose to add a watermark to shared files, you can determine whether the watermarks on all files are rasterized, or whether watermarks are vector-based or rasterized, depending on the file type.Watermarking
Determines how watermarking is applied to different file types. Select:- Vector-based and rasterized watermarking (recommended) - Provides infinite resolution, inclusion in search, clickable links, and a very small sized file overhead, but can and is used on document-based files only. Rasterized watermarking is used on all image files. The “document-based files” on which vector-based watermarks can be applied are also known as files that have PDF support. Those file types are listed in the Supported File Types topic with a Yes in the PDF Support? column.
- Note Watermark types are applied automatically based on file type when users add watermarks to files or folders.
- Rasterized watermarking only (default) - Provides increased security, but no resolution scaling, no searchability, no clickable links, a moderate file size overhead, and reduced usability. This watermark type can’t be removed without damaging the underlying content.
- Video Watermarking enabled for all managed users - Provides a visible watermark overlay on video previews in the Box Web App.
Custom Watermarking
Enables your organization’s Box users to select and configure the following watermark properties:- Pattern
- Text
- Text Size
- Text Color
- Opacity
- Position
- Rotation
- Whether to apply the watermark to all files in a folder
Watermarking Differences
The different types of watermarking have differences that may affect your decision about which one to use.| Vector-based | Raster | |
|---|---|---|
| Resolution | Infinite; the watermark scales when viewers zoom in or out | Limited to 2048 x 2048 pixels; the watermark does not scale when zooming |
| Text copying | Yes | No |
| Text searching | Yes | No |
| Links | Clickable | Not clickable |
| Modifies underlying content | No | Yes |
| Watermarked document size | Smaller | Larger |
| Document security | Medium | High |
Watermarking Use Cases
Use the Vector-based and rasterized watermarking option:- When dealing with large files that need to maintain readability, documents such as blueprints, diagrams, or files containing a lot of small print.
- When dealing with text-based files where text needs to be copied and searched for or when hyperlinks need to be clickable.
- When you have storage or bandwidth concerns with the size of watermarked files being shared.
- When you want to lock down the watermarked file by not allowing any text to be copied.
- When the content in question is of the highest sensitivity level. Note that while watermarking is a security deterrent, a very motivated and technically adept hacker can remove a vector watermark. Doing this impacts the original formatting of the underlying document. This is slightly different from a Rasterized watermark where you cannot remove the watermark without destroying the underlying content as well.
Content Creation
This section allows you to restrict certain types of content creation. Higher restrictions provide admins greater control over the content and structure. However, users are more restricted in creating content, which may impact the amount of collaboration.Restrict content creation
Determines who can create and delete folders, files, and bookmarks at the root level of your Box instance. Select this option to prevent all non-admin managed users from creating, deleting, and moving folders in their “Files” section. Enable this setting to create the folder structure for the entire account and then invite users into this structure. Note:- If Only admins can create and delete first-level folders, files, and bookmarks is enabled:
- Admins can transfer ownership of folders to managed users, but managed users cannot transfer ownership to others.
- Only admins and co-admins with the requisite permissions can create, copy, move, and delete content at the root level. As a result, actions such as certain report exports (e.g. Access Stats), which generate a Box Reports folder in the user’s root directory, fail for non-admin users when this setting is active.
Restrict tag creation
Cleared by default. Determines who can create tags for files in your account. Tags can be used by users to easily label and search for content. Select this option to limit tag creation, and then select who can create tags from:- Folder owners/co-owners and admins/co-admins (default)
- Admins/co-admins
Email Uploads
Determines whether you to allow people to upload file attachments to a specific Box folder through email. The default state is cleared.Folder Insights
Folder Insights allow folder owners to track activity in folders they own.Configure Folder Insights
Defines who can use Folder Insights. Click Edit Configuration and then select:- Disable for all managed users
- Enable for all managed users (default)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
Hubs
Box Hubs is a curation and publication tool that enables teams to create portals from their content in Box. This setting defines who in your organization can view, create, and share Hubs. Box enables you to enter up to 100 names or email addresses, and up to 100 groups. If you want to enable or disable more, enable or disable File Request for the entire organization. You can select only groups whose Permission Setting is Admins Only. For details about group permissions, see Creating and managing groups.Configure Hubs
Defines who can use Box Hubs. Click Configure and then select:- Disable for all Hubs users (default)
- Enable for all Hubs users (recommended)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
File Request
File Request enables users to request files and metadata from anyone with a linkFile request users
Defines who can request files. Click Configure Users and then select:- Disable for all managed users
- Enable for all managed users (recommended) (default)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
- You can enter up to 100 names/email addresses and up to 100 groups. If you want to enable or disable more, you’ll have to enable or disable File Request for the entire organization.
- You can only select groups that have Permission Setting set to Admins Only. For details, see Creating and managing groups.
File request permissions
Defines what folder owner roles are allowed to make file requests. Click Configure Permissions and then select:- Owners/co-owners
- Owners/co-owners and editors (recommended) (default)
File Request Link Access
Defines whether file uploaders are required to sign in with a Box account. When selected, this setting:- Applies enterprise-wide; individual Box account holders cannot change it
- Applies retroactively to all currently active file requests in addition to all future file requests
- Disables the option to add an email field to the file request, as that option becomes redundant when you require a Box login before uploading
- Provides an option for people without a Box account to create one before they can submit
Automate
Managing Box Automate access To manage Box Automate for end users, admin must configure the enablement settings within the Admin Console. Configuring Box Automate settings- Navigate to the Admin Console > Enterprise Settings.
- Select the Content & Sharing tab.
- Scroll to the Box Automate section.
- Under the enablement settings, click Edit configuration.
- Under User Access:
- Enable for all users
- Disable for all
- Enable for some users
- Disable for some users
- Click Save to apply changes.
- Under workflow creations enablement, click Edit configuration.
- Select the user roles:
- Owners/co-owners
- Owners/co-oweners and editors
- Click Save to apply changes.
- Disabling Box Automate at the enterprise level immediately pauses all active workflows. Use caution when modifying global enablement settings.
- The setting within Admin Console > Content & Sharing labeled Prevent collaborators from moving or copying content to a folder where they have a higher permission level is not applicable to actions performed by Automate Workflows executions.
- User Access Management: Use the allowlist settings in Enterprise Settings to ensure only authorized personnel or specific departments can build automations.
Relay
Relay allows users to build workflows to automate tasks and content actions within Box. If enabled, your users are able to build automated workflows on folders they own or co-own.Relay users
Defines who can use Relay. Click Edit Configuration and then select:- Disable for all managed users
- Enable for all managed users (recommended) (default)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
- You can enter up to 100 names/email addresses and up to 100 groups. If you want to enable or disable more, you have to enable or disable Relay for the entire organization.
- You can only select groups that have Permission Setting set to Admins Only. For details, see Creating and managing groups.
Relay permissions
Defines who can define and launch workflows from folders they own, co-own, or can edit. Click Edit Configuration and then select:- Owners/co-owners
- Owners/co-owners and editors (recommended) (default)
Template publication permissions
Defines who can publish workflow templates. Click Edit Configuration and then select:- Only Relay Admins and Co-admins can publish workflow templates
- Enabled Relay users can publish workflow templates (recommended) (default)
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
- You can enter up to 100 names/email addresses and up to 100 groups. If you want to enable or disable more, enable or disable template publication for the entire organization.
- You can only select groups that have Permission Setting set to Admins Only. For details, see Creating and managing groups.
Box Doc Gen
Box Doc Gen enables users to generate dynamic documents with Doc Gen APIs.Box Doc Gen Permissions
Defines who can create and manage Doc Gen templates. Click Configure and then select:- Disable for all managed users (default)
- Enable for all managed users
- Enable for select users and groups, and then enter one or more user names, email addresses, or groups
- Enable for everyone except select users and groups, and then enter one or more user names, email addresses, or groups
Cascading Folder Level Metadata
Cascading Folder Level Metadata enables users to cascade a metadata template and its attribute values to new or existing folder contents. To be granted Cascade permissions through this setting, users must have permission to edit the folder-level metadata.Cascading folder level metadata permissions
Defines who can can create cascade policies. Click Configure and then select:- Disable for all managed users (default)
- Enable for all managed users
- Enable for select users, and then enter one or more user names or email addresses
- Enable for everyone except select users, and then enter one or more user names or email addresses
Auto-Expiration
This is where you define default expiration for shared links and invited collaborators.Shared links expiration settings
Disable all shared links after a specified time of link creation
Determines whether all shared links are disabled after the defined number of days. Note If you set shared links to be disabled automatically, the content itself is not deleted. It is just unshared. The default state is selected and the default time period is 60 days. The limit for auto-expiration is 18250 days.Disable public shared links after a specified time of link creation
Default is selected with a value of 60 days. Determines whether only publicly shared links are disabled after the defined number of days. Note If you set shared links to be disabled automatically, the content itself is not deleted. It is just unshared. The default state is selected and the default time period is 60 days. The limit for auto-expiration is 18250 days.Apply these settings to
Determines what content that shared link expiration applies to. Select from:- Folders and Files
- Folders only (default)
- Files only
Notify item owners a specified time before expiration
Determines if content owners with shared links are notified before the shared links expire. The default state is cleared. The default time period when selected is 7 days.Allow item owners and editors to modify the expiration date
Determines whether owners of content can change expiration dates for any shared links they create. The default state is selected. Note If you clear this setting, any existing shared links with expirations are not modifiable. Box does not recommend this configuration.Invited collaborators expiration settings
Automatically remove invited collaborators
Determines whether collaborators are removed after the defined number of days. The default state is cleared. When selected, the default time period is 60 days. The limit for auto-expiration is 18250 days.Allow folder owners to extend the expiration date
Available only if Automatically remove invited collaborators is selected. Determines if folder owners can extend a collaboration expiration date. The default state is selected.Notify affected users n days before expiration
Available only if Automatically remove invited collaborators is selected. Determines if collaborators receive notifications through email before a collaboration expires. The default state is selected and the default time period is 7 days Note Box sends email notifications to the owner and any co-owners of the corresponding folder. Box only notifies co-owners who are directly collaborating on items with a pending expiration. Box does not notify co-owners who are collaborating through inherited permissions.Apply these settings to
Available only if Automatically remove invited collaborators is selected. Defines the collaborators that these expiration settings apply to. Select from:- External Collaborators (default)
- All Collaborators
Disposition Insights
When enabled, our dispositions functionality allows users in your organization to view files that are set to be disposed of due to retention policies. This helps to prevent valuable content from being lost by providing in-platform visibility into content expiration. Depending on settings, the disposition date can be extended. The setting is disabled for all managed users by default. Dispositions can be configured in four ways:- Disable for all managed users: No one can access the dispositions page.
- Enable for all managed users: All users can access the dispositions page.
- Enabled for select users and groups: Selected users and groups can access the dispositions page.
- Enable for everyone except select users and groups: Everyone apart from selected users and groups can access the dispositions page.
- Admin Console > Governance.
- Click into the Retention tab.
- Select Create Retention Policy.
Notes:
- After turning on the disposition page setting for at least one person, Box starts processing the enterprise data needed to generate disposition insights. It can take up to around 72 hours until the data starts to display.
- When this feature is enabled, the global Metadata dispositionInsights template is automatically applied to retained content. The template includes information about the retention expiration date and disposition action. This information is accessible through our API, with Metadata template API documentation available.
- If you already use Metadata APIs to collect information about the templates, make sure you use the appropriate scope parameter.
- Different endpoints are used to retrieve metadata template details, depending on the scope:
- We prioritize the processing of files expiring in the next 12 months, then asynchronously process content expiring further in the future. This may lead to a situation where content expiring further in the future gradually displays in the subsequent days after enablement.
- Similarly, when you apply a retention policy to new content, the data starts appearing on the page within 72 hours. If you apply it to a large number of files (e.g. hundreds of millions) it appears gradually over the following days.
Trash
Enabling trash provides each of your users with their own trash folder. This is recommended so users can retrieve items they may have accidentally deleted.Enable Trash
Determines whether Trash is used in your organization. The default state is selected.People who can permanently delete content in Trash
Available only if Enable Trash is selected. Determines who can permanently delete content once it has been sent to Trash. Select from:- Everybody (including Automation and Policies) (default) - Anyone in your organization can delete content from Trash that is not otherwise retained by policy.
- Nobody (No user or policy can delete content) - Retention policies with disposition action set to Permanently delete content do not permanently delete content that has reached the end of the retention period.
- Admin Only - Only your organization Admin can delete content from Trash, and only content not otherwise retained by policy.
- Admin and Co-admins Only - Only Admins and Co-admins can delete content from Trash, and only content not otherwise retained by policy.
- Policy Only (No user can delete content) - Only policies can delete content from Trash. Retention policies with disposition action set to Permanently delete content are allowed to delete content that has reached the end of the retention period. The Items in trash are automatically deleted after Trash policy deletes content based on the time period selected except for items retained by a Governance policy.
- Selected Users - (Available only when you have the Box Governance package.) Enter up to 1000 user names. (Groups are not supported.) If you do not enter any users, it operates the same as if you select Policy Only.
- Changes to this setting are not retroactive; they apply only to the content moved to Trash after the setting change is applied. All content already in Trash gets purged according to the setting value that was applied to it when it was sent to Trash.
- Legal Holds and Retention policies take precedence over this Trash setting: Any content under retention or legal hold is not permanently deleted.
Items in trash are automatically deleted after
This setting is available only if Enable Trash is selected. Determines how long content is in Trash of your managed users’ accounts before it is permanently deleted. After the specified time period passes, the items are permanently deleted. If you modify this setting, the new duration does not apply retroactively to items already in the trash. Select from:- 7 days
- 14 days
- 30 days (default)
- 60 days
- 90 days
- Custom - The ability to choose the Custom option is only available as part of the Box Governance package. The Custom option can range from 7 days to 10 years.
- Never auto-delete items (including by policy)