Back to vendors
B

Box

Also known as: Box Agent, Box AI Studio, Box AI

Visit site
Entry priceBox has public per user Business plans, but the Box Agent requires Enterprise Plus or Enterprise Advanced, which are quotedFull pricing detail

Intelligent Content Management platform whose Box Agent reasons over a company's unstructured content to search, analyze, and generate files across multi step tasks, paired with the Box AI Studio agent builder, all grounded in authorized content with enterprise security, model choice, and an MCP server.

Box is an intelligent content management platform that has built its agent layer on top of the content it already stores. The Box Agent takes natural-language instructions and works across a company's files: searching what the user is permitted to see, analyzing and synthesizing across large document sets, and generating new files in Box Notes, Word, PDF, Excel and PowerPoint, with a Pro Mode for deeper recursive reasoning and an Expanded Mode for larger context.

Box AI Studio is the agent builder, available on Enterprise Advanced. An admin gives an agent a name and description, custom instructions that set its reasoning style and can enforce step-by-step workflows, and knowledge bindings to named files or Hubs referenced with @mentions, including priority rules when sources conflict. Instructions cannot override human approval workflows, break safety policies enforced in code, reach restricted classifications, or force a tool the user's permissions block.

Admins choose the model per agent, selecting Auto or a provider from the list approved for their organization, and restrict what the agent may do, including read, write, move, delete, share and email. Before release, agents are exercised in a Playground against real content, and an agent's availability across AI Home, Files and Hubs expands as it passes evaluation tests for more complex knowledge configurations.

Everything runs inside Box's permission model: answers come only from content the user may see, classification and retention rules apply, responses cite their sources, and Box states customer data is not used to train third-party models.

Admins watch usage through AI Insights in the Admin Console, with queries over time, usage by product, top agents by usage and downloadable per-user and per-agent activity reports, alongside audit trails across hundreds of content actions.

Box Zones gives customers a choice of storage region across ten regions, and Box publishes FedRAMP certification, ISO 27001, PCI DSS Level 1, SOC 1/2/3, HIPAA and ISO 27018. External agents reach Box content through a Box MCP server.

Box acts on content rather than driving a browser, and its agent capabilities sit on the Enterprise Plus and Enterprise Advanced plans.

Vendor details

Canonical URL

https://www.box.com

Category

Enterprise operations agent

Subcategory

AI agents and agent builder for enterprise content

Funding status

Independent and publicly traded on the New York Stock Exchange under the ticker BOX, headquartered in Redwood City, California, founded in 2005 by chief executive Aaron Levie and Dylan Smith. Box serves leading global organizations including JLL, Morgan Stanley, and Nationwide, was named a Leader in the 2026 Gartner Magic Quadrant for Document Management, and made the Box Agent generally available in April 2026 as part of a broad transformation into an AI powered enterprise content platform.

Company status

independent

Use cases & customers

Primary use cases

content search and Q&Acontract and document reviewcontent generation and reportscustom content agents

Target customers

large enterprisesregulated industries and legal, finance, and HR teamsorganizations standardized on Box for content

Deployment options

SaaScloud

Integrations

Box serves a Box MCP server so external platforms, including Claude, Microsoft Copilot, GitHub Copilot, Glean and custom LLMs, can reach Box content under the user's permissions, and publishes a developer platform with APIs and an AI Studio API. Agents act on content inside Box and generate files in Box Notes, Word, PDF, Excel and PowerPoint. Integrations into systems outside Box are not documented on the pages read.

In practice

Your team wastes hours hunting through thousands of files and manually reviewing contracts. The Box Agent searches your permitted content, compares contracts against standard terms, flags the exceptions that matter, and cites every source.

You want custom AI agents for repeatable, high stakes work but cannot risk them touching the wrong data. Box AI Studio lets admins scope agents to approved files, set action guardrails, choose the model, and validate behavior in a Playground before rollout.

You need to answer a fifty page RFP fast without leaking sensitive material. The Box Agent autonomously searches your compliance guides and whitepapers, drafts a grounded response in minutes, and respects every user permission and retention rule.

Agentic Index coverage score

10.5 / 14 capabilities · 75%

Integrations & Tool Calling Full

Enterprise content is what Box agents act on, and they write as well as read. They search, analyze and create files in Box Notes, Word, PDF, Excel and PowerPoint, with availability set across AI Home, Files and Hubs, and permissions gate every action. Box serves a Box MCP server so external platforms reach Box content, publishes an AI Studio API and a developer platform, and custom agents can query images and spreadsheets.

No integrations that reach systems outside Box, such as a CRM or a ticketing system, are documented; what the agents act on is content and the platform around it.

Sourcebox.com/agents, /ai/ai-studio (index copies); docs.box.com/en/box-ai/creating-and-configuring-agents; readread 2026-09-17

Workflow Orchestration Full

Multi step work is driven by instructions and modes rather than a workflow builder. Custom instructions can enforce step by step workflows ("first analyze, then propose, then act"), direct the agent to favor certain tools when several are available, and specify structured output.

Pro Mode supports "advanced agent behaviors such as recursive reasoning and enhanced document or video analysis", and Expanded Mode lets queries exceed standard limits. The Box Agent completes multi step tasks across content, locating files, analyzing large document sets and generating new files, iterating in agentic loops.

There is no workflow surface with branches and retries, and no versioning is documented. Whether Box Automate workflows can invoke an agent step was not established.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents; box.com/agents (index copy); readread 2026-09-17

Knowledge Grounding & RAG Full

Agents are grounded in specific, permission aware content. An agent's Knowledge setting "binds the agent to specific files, or Hubs for reference". Knowledge sources are referenced with @mentions in custom instructions, with explicit priority rules when they conflict (a single source of truth, or ProductSpecs highest, ReleaseNotes second and FAQ lowest), which Box says "ensures agents remain grounded in authoritative sources".

Box AI "pulls information only from the document you loaded in preview" and tells the user when a question falls outside it. AI Studio "reduces hallucinations by grounding agents in specific, admin-approved files or Hubs", responses cite their sources, and custom agents can query images and spreadsheets. Hubs act as bindable, maintained knowledge scopes over the customer's content.

How Hub contents refresh is not described.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents; box.com/ai/ai-studio, /agents (index copies); readread 2026-09-17

Human Oversight & Guardrails Full

Admins set guardrails on each action, and agents cannot override approval workflows. AI Studio governance includes "applying policy-based guardrails on actions, validating inputs for prompt injection... and keeping humans accountable for consequential decisions", and admins can "restrict actions such as read, write, move, delete, share, and email through guardrails" and switch capabilities such as search and content creation on or off.

The configuration docs state that custom instructions "cannot override human approval workflows, break safety policies enforced in code, access restricted data or classifications, or force tool execution when permissions block them", and instructions can tell the agent to prioritize verification before responding or to ask when unsure.

The docs refer to the approval workflow without describing where an approval step is configured or how it is routed.

Sourcebox.com/ai/ai-studio (index copy); docs.box.com/en/box-ai/creating-and-configuring-agents; readread 2026-09-17

Security, Identity & Governance Full

Deep attestations sit alongside permission aware agents. Box's FedRAMP page states "Box holds a FedRAMP Class D certification, previously described as FedRAMP High authorized". The information governance page says Box "meets FedRAMP, FIPS 140-2, ISO 27001, and PCI DSS Level 1 standards" and "maintains certified compliance with HIPAA/HITECH and ISO 27018", and reports SOC 1/2/3. The Trust Center describes an information security management system based on ISO 27001 and NIST 800-53, with SOC reports available under NDA.

Agents answer only from content the user may see and respect existing permissions, classification and retention by default. AI Studio admins restrict agent actions, including read, write, move, delete, share and email, scope knowledge to named files or Hubs, control where an agent appears, and manage which users may use it. Box states customer data is not used to train third party models.

Sourcebox.com/trust, /fedramp, /security/information-governance (index copies); docs.box.com/en/box-ai/creating-and-configuring-agents; readread 2026-09-17

Observability & Auditability Partial

Admins see AI usage by agent and by user, but not a step by step record of each agent run. Admin AI Insights adds "an AI usage dashboard" in the Admin Console with AI queries over time, AI usage by product, and top agents by usage, both chargeable and non chargeable.

Admins can "download detailed user activity reports to break down unit spend by individual user or specific agent", and the Admin Console carries "extensive audit trails for more than 300 actions", with AI usage on the dashboard. AI Studio governance lists maintaining audit trails and logs. The AI Unit insight card runs about two hours behind.

No per run trace of an agent's steps, tool calls or retrieved content is documented. Citations show the sources behind an answer, which is grounding rather than a run record.

Sourceblog.box.com/introducing-admin-ai-insights, box.com/security/it-admin-controls (index copies); docs.box.com/en/box-ai/understanding-ai-units-in-box; readread 2026-09-17

Memory & State Persistence Not documented

Whether Box agents keep memory is not settled. The agent configuration documentation sets out every element (details, custom instructions, knowledge, suggested prompts, availability, advanced model settings, Pro Mode and Expanded Mode), and none is a memory, session state or learned context surface. The AI Studio and Box Agent pages describe grounding and modes, not memory, and grounding in enterprise content on each run is knowledge rather than memory.

Box's AI documentation runs to several hundred pages, so a memory feature could sit somewhere not covered here. Nothing published describes Box Agent session history or a memory store with a stated scope and lifetime.

Sourcedocs.box.com/llms.txt, /en/box-ai/creating-and-configuring-agents; tried; docs.box.com/_llms/en/ai.mdread 2026-09-17

Deployment & Data Residency Full

Customers choose the region where their content is stored. A box.com announcement reads: "Box Zones expands to 10 regions. Switzerland, Singapore, and Israel now available." Box is managed cloud with that regional choice.

There is no on premises or customer cloud deployment, and only three of the ten regions are named in the material available.

Sourcebox.com/security/it-admin-controls and Box Zones announcement (index copies); readread 2026-09-17

Prebuilt Agents, Templates & Packs Partial

Admins get a builder rather than prebuilt agents. AI Studio starts from New Agent, where the admin supplies a name, custom instructions, knowledge bindings, up to four suggested prompts, availability and model settings. The AI Studio page lists use cases a customer could build, such as extracting NDAs and liabilities from data room documents or pulling KYC details from onboarding forms, but these are examples, not adoptable assets. Neither the AI Studio page nor the agent docs offer a prebuilt agent set, template gallery or catalog.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents; box.com/ai/ai-studio (index copy); readread 2026-09-17

Triggers & Channel Coverage Partial

Every documented way into a Box agent is a person asking. Agents appear where admins publish them, in AI Home, Files and Hubs, and answer when a user asks, with suggested prompts to start an interaction. Box Automate and Relay trigger content workflows on content events, but nothing documents a Box Automate workflow invoking an agent step. No schedule, event or telemetry trigger that starts an agent is published.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents; box.com/agents (index copy); readread 2026-09-17

Model Flexibility & Routing Full

Admins choose the model for each agent. An agent's Advanced settings "choose what model the agent uses when answering questions: you can select Auto or from the list of other providers available in your organization". Pro Mode is on by default, so the agent "uses higher thinking levels and may access more capable and newer models", and the AI units guidance tells admins to use Standard models or Auto for routine work and keep Premium models for complex reasoning. The AI Studio page offers to "select from the most powerful AI models from leading providers like Anthropic, Google, and OpenAI".

Bringing your own model or customer hosted inference is not offered; choice is from Box's provider list.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents, /en/box-ai/understanding-ai-units-in-box; box.com/ai/ai-studio (index copy); readread 2026-09-17

APIs, SDKs & MCP Extensibility Full

Outside agents can reach Box content, and Box publishes developer APIs. Box offers "Box-native agents in Box Agent and Box AI Studio, and third-party platforms accessing Box content through MCP server, including Claude, Microsoft Copilot, GitHub Copilot, Glean, and custom LLMs", so Box serves MCP to outside agents. It also publishes a developer platform (developer.box.com) with APIs and an AI Studio API, and agents generate files in Box Notes, Word, PDF, Excel and PowerPoint for use elsewhere.

Box agents consuming external MCP tools is not documented, though this comes from the product pages rather than the developer reference.

Sourcebox.com/ai/ai-studio, /agents (index copies); readread 2026-09-17

Testing, Debugging & Optimization Full

Agents are tested before release, and evaluation tests gate where they can be published. AI Studio includes a Playground where admins "validate behavior, refine instructions, and confirm grounding before broader deployment", using custom suggested prompts against real Box content and swapping models in the same session. The configuration docs add: "Availability expands as your agent passes evaluation tests for increasingly complex knowledge configurations, from single files to multiple files, and Hubs." Passing those tests is the release path.

Box does not describe the evaluation tests in detail, and no scored regression suite is published.

Sourcedocs.box.com/en/box-ai/creating-and-configuring-agents; box.com/ai/ai-studio (index copy); readread 2026-09-17

Browser & Computer Use Not documented

Content, not screens, is where these agents work. They search permitted files, analyze document sets and generate files inside Box, and external systems reach Box through its MCP server rather than Box operating their interfaces. No browser, desktop or screen control capability is documented; the agent's tools are content operations. With no bot or screen automation estate, breakage when an interface changes is not a concern.

Sourcebox.com/agents, /ai/ai-studio (index copies); docs.box.com/en/box-ai/creating-and-configuring-agents; readread 2026-09-17

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-30·Observability / auditabilityVerified

Values extracted by Box Extract agents now come with citations in Box Preview, so clicking one jumps to the exact spot in the original file and highlights the source text. When a reviewer edits or deletes a value, its highlight disappears, so the field reads as confirmed by a person rather than generated.

Bears on: Human approval / guardrails

View source
2026-09-24·MCP / tool calling / APIVerified

Box introduced Doc Split APIs to divide a PDF into separate documents and save them to a chosen Box folder. Manual mode uses explicit page ranges, while smart mode interprets natural language instructions such as splitting at QR code separators or isolating signature pages. The asynchronous API creates a job through POST /2.0/document_splits and exposes its status and generated files through a GET endpoint. Requests use API version 2026.0, and smart splits consume one AI Unit per four pages.

Bears on: Workflow orchestration

View source
2026-09-14·Security / enterprisePartially Verified

Box added admin model controls for the Box Agent, giving administrators more governance over which models the agent uses and how it operates in their organization.

Bears on: Security / enterprise

View source
View all 10 changes for Box →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Box has public per user Business plans, but the Box Agent requires Enterprise Plus or Enterprise Advanced, which are quoted

per user enterprise plans, with AI capabilities gated to Enterprise Plus and Enterprise Advanced

Trial available

What is public

Box publishes per user Business plans, but the Box Agent needs Enterprise Plus or Enterprise Advanced and AI Studio needs Enterprise Advanced, and those tiers are quoted rather than listed.

Billing mechanics

Per user subscription plans, with base Business tiers published and the AI capabilities, the Box Agent and Box AI Studio, gated to the quoted Enterprise Plus and Enterprise Advanced tiers.

Cost watchouts

The Box Agent and AI Studio are gated to the Enterprise Plus and Enterprise Advanced tiers, and file creation and Pro and Expanded modes are beta or Enterprise Advanced only, so AI value depends on the higher, quoted tiers.

Variable cost rationale

AI capabilities require higher enterprise tiers and add agentic model usage on top of per user licensing, so cost grows with users and AI usage.

Additional watchouts

Confirm which enterprise tier is required for the Box Agent and AI Studio, that file creation and Pro and Expanded modes fit your plan, and how AI usage is metered.

Sales call required

Yes, required for paid access

Free / trial

Free trial available; the Box Agent requires an Enterprise Plus or Enterprise Advanced plan

Lowest paid plan

Box has public per user Business plans, but the Box Agent requires Enterprise Plus or Enterprise Advanced, which are quoted

Key ambiguities

Base Box plans are public per user, but the enterprise tiers required for the Box Agent and AI Studio are not publicly priced, and AI usage limits are not fully disclosed.

Agentic Index verified 2026-07-07

Alternatives to Box

The closest documented capability profiles to Box among enterprise operations agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Beam AI12.0 / 14Fuller documented coverage on Observability & Auditability and Prebuilt Agents, Templates & Packs
  • Oracle12.0 / 14Adds documented Memory & State Persistence
  • Boomi12.5 / 14Adds documented Memory & State Persistence
  • Fabrix.ai12.5 / 14Adds documented Memory & State Persistence
  • Forest10.5 / 14Fuller documented coverage on Observability & Auditability and Triggers & Channel Coverage
  • Salesforce12.5 / 14Adds documented Memory & State Persistence

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.