DocsSign inInstall Kastel
All connectors

A Box file is readable by an AI only when its folder's collaborations say so clearly.

With Kastel

When a Box file comes into your Kastel, it is its parent folder that decides who will be able to read it, and that folder's collaborations are the only signal used. A file sitting in the root, a folder shared with a Box group or a link opened to the whole company all put the file on hold until an administrator settles it.

In Box, the parent folder answers for its files

Box was built around the folder. You invite collaborators into it, you give them a role, and whatever goes into that folder inherits the invitation. The connector follows that logic all the way and looks for no signal elsewhere.

For every file it opens the collaborator list of the folder holding it directly. When those collaborators all belong to the same department of your organisation, the file is filed under that department. When the list does not allow a decision, the file waits for an administrator, and three very ordinary Box situations fall into that case.

A folder shared with a Box group puts its files on hold, because the connector does not open a group to list the people in it. A link shared with the whole company does the same, since it designates everyone without designating anyone. And a file sitting directly in All Files has no collaborated folder above it, so there is no audience to inherit.

A Box file is filed under a precise department, or it stays on hold. The connector holds no middle position and there is no common pool where it would drop what it could not classify. Opening access to a file on hold is a decision, it belongs to an administrator, and that is the subject of the governance of your context.

What happens to one Box file, step by step

Every step can stop the file, and none of them lets it go further than itself when there is any doubt.

  1. The tree is walked from the root

    The connector goes down folder by folder from All Files, paging each folder to the end. If the tree is too vast or if it loops, the pass fails outright instead of settling for a partial walk. A partial walk would make the reconciliation believe the unvisited files no longer exist, and that kind of loss goes unnoticed.

  2. The modification date decides whether anything is new

    The connector keeps the most recent modification date it has seen and only rereads the files newer than that marker. A file for which Box gives no usable date is reread on every pass, as a precaution, and rereading it changes nothing when its content has not moved.

  3. Formats with no readable text stop there

    A file whose format is not on the list of formats read is not even downloaded. Office documents, PDFs, text files and images of scanned documents carry on. Character recognition runs on your own machine, so the image of a scanned contract is sent to no service to be deciphered, and the text that comes out then follows the same rules as everything else.

  4. The parent folder's collaborations are paged to the end

    The connector reads the folder's full collaborator list, page by page. A list it cannot page through entirely puts the file on hold, because concluding from a partial page would mean opening an access on incomplete information.

  5. The content is downloaded from Box, and nowhere else

    Box does not serve the content directly, it redirects to a signed download address on its own storage servers. The connector checks that each address really belongs to Box before following it, and it follows no redirect automatically. A file larger than the ceiling is refused before the download, based on the size Box declares.

  6. The text is filed, or put on hold

    The extracted text is filed under the department the collaborations designated. When they designated nobody, the file still comes into your Kastel and stays unreadable to every connected AI, until an administrator settles it.

What the connector fetches, and what it ignores

Box exposes a great many objects around a file, from comments through to classification labels. The connector asks only for what it takes to read a document and to know who is allowed to see it.

What your Kastel reads in Box

  • The files in the tree the connected Box account can see
  • The text of documents, workbooks and decks, Office and OpenDocument
  • PDFs and scanned documents, through character recognition
  • The collaborations on each file's parent folder

What it never reads

  • The comments, tasks and annotations on a file
  • Custom metadata and Box classification labels
  • The earlier versions of a file, and the trash
  • Formats that carry no readable text

A Box file's classification label plays no part in the access decision, and that is a limit of the connector today. What decides is the parent folder's collaborator list, because that is the signal Box itself keeps current on every invitation and every departure.

What Box's traversal will never tell you

Box keeps no change log the connector can follow. Each pass walks the tree again and compares dates, which is enough for a content change and not enough for two other things.

A deletion appears nowhere. A deleted file is simply absent from the next walk, and it is the reconciliation that notices, by comparing what it tracks against what Box returns. On this point Box is less talkative than Dropbox, whose change feed names its deletions.

A collaboration change does not appear either. Adding or removing a collaborator on a folder does not touch the modification date of the files it holds, so nothing moves as far as dates are concerned. The reconciliation rereads the collaborations of every tracked folder and moves the files whose department changed, in both directions. Between two reconciliations, a file keeps the department it had.

That lag is the price of Box's model, and it only concerns the filing of a file already read. The other sources in the connector catalogue each have their own audience signal and their own cadence, and none inherits another's rules.

What this connector does not do

It does not see a collaboration set on a single file. Box lets you invite somebody onto one specific file without touching the folder, and the connector reads the parent folder's collaborations only. That file therefore waits for an administrator, even though its sharing is perfectly clear to you.

It does not use Box's classifications. An organisation that has labelled its documents in Box will not find those labels in the access decision, which rests entirely on the parent folder's collaborations. If your classification is the reference in your organisation, this connector does not inherit it.

It only notices a deletion at reconciliation. The ordinary walk says nothing about a deleted file, it merely records its absence. And when the reconciliation does record it, the content is not erased from your Kastel, it is marked there as gone at the source and kept, until an administrator decides to erase it.

No write action is possible. The authorisation requested from Box is called root_readonly and covers reading only; any authorisation carrying the word write is refused before the first call. Removing the connection stops the reading and removes nothing of what already came in.

See what each plan adds to the free core.

Every connector, Box included, is in the free core to self-host. The pricing page says what the paid plans add on top, who they are for, and the team size at which the question starts to arise.

See pricing
Other connectors in detail
Google Drive
The sharing already set on each file decides what an AI reads.
Dropbox
The shared folder's membership decides, and a file on its own is read by nobody.
Microsoft 365
Mail received and sent, plus documents shared with named people.

See the full connector catalogue