Box Agent
Box Agent is the default, general AI agent experience in Box AI. Box documents it as an agentic loop that plans a request into a visible to-do list, selects capabilities such as searching a drive, extracting data points or invoking a Custom Agent built in Box AI Studio, and synthesises a final deliverable in the conversation. It operates across Box AI Home, Preview, Notes and Hubs, searches content the requesting user can already access through permissions and collaboration settings, and is offered in Standard, Pro and Expanded modes. Box documentation reviewed for this record does not establish that Box Agent itself writes, moves or deletes Box content, changes metadata or starts workflows.
Recorded characteristics
- Function
- Box documents Box Agent as the default agent selected when using Box AI Home, and as the shared AI agent experience across Preview, Files (multi-document), Notes and Hubs. Box describes a default agentic loop with four documented elements: upfront planning, in which the Agent breaks complex goals into manageable steps and creates a visible to-do list of its reasoning; capability selection, in which it selects the appropriate tools, whether searching an entire drive, extracting data points, or invoking a Custom Agent built in Box AI Studio; agent-to-human collaboration, in which users add and preview sources within the flow of work; and autonomous execution, in which the Agent synthesises information into a final deliverable. On submission of a prompt the Box Agent searches all content accessible to the user through permissions and collaboration settings and returns a response the user can continue working on. Documented user-facing task types are summarising content, researching files, analysing patterns and creating templates, drafts and outlines. Box AI Home sessions are persistent, with session history that users can view and resume. Box describes the Enterprise Plus entitlement as the integrated Box Agent providing UI-driven, multi-step task execution. Box's own delivered outputs are returned in the conversation; saving them is a user action (Copy, Save as Note, or Add to Note in Box Notes). Box Agent is distinct from a Custom Agent created in Box AI Studio: a Custom Agent is a separately configured agent with its own instructions, knowledge, availability and model, and Box documents Box Agent as able to invoke a Custom Agent as one of its available capabilities; invoking a Custom Agent does not make every Custom Agent configuration part of this record. This record also excludes Box Extract, Box Automate, Box for Agentforce, the Box AI Agent in Microsoft 365 Copilot, the Box AI APIs and the Box MCP server.
- Data access
- Box documents Box Agent as searching all content accessible to the requesting user through existing permissions and collaboration settings; Box states more generally that Box AI respects all user permissions and enterprise security policies. Access is therefore user-scoped, not organisation-wide. Users can narrow or extend what the Agent uses by adding sources: dragging and dropping from a device or external drive, dragging from the left navigation (Recents or Collections), uploading from a device, or @ mentioning a user or content, and by adding files, folders or an entire Hub as sources. In Preview the previewed file is automatically a source; in a Hub the Hub's content is the source and sources outside the current Hub cannot be added; in Notes the current Note is the source. Where the Box Agent invokes a Custom Agent, that Custom Agent's own configured knowledge (files and Hubs attached in Box AI Studio) applies to that invocation. Documented content constraints include a 2MB text limit per file (larger files process only the first 2MB), a 10-file limit for multi-document queries, query character limits (1,000 characters for legacy agents; 64,000 characters for new agents), image handling at a maximum of 2048 x 2048 pixels and up to 10 pages for multi-page image formats, and Hub file limits. AI Home retains session history that users can resume, clear or permanently delete.
- Actions
- Generative only
- External actions
- Unknown
- Human confirmation
- Not established
- Permission basis
- User permissions
- Administrative control
- Box AI must first be provisioned and enabled for the organisation; an admin enables Box AI from the Box AI section of the Admin Console Settings tab, and must review and accept the Box AI Product Addendum before enabling, with some organisations shown a Review Agreement Offline message requiring contact with Box. Within the Box AI settings, admins configure access separately for AI Home, Preview, Notes, Hubs, Extract, the AI API and Official Box Integrations, and separately for Box AI Studio. For Box AI for AI Home the documented options are: disable for all managed users; enable for all managed users (marked Default); enable for select users and groups; or enable for everyone except select users and groups, with a documented limit of 100 names or email addresses and 100 groups, and group selection restricted to groups whose Permission Setting is Admins Only. The list of agents and models available to a user depends on what the admin has enabled for the organisation; choosing a model is available only to Enterprise Advanced. Consumption is governed by a per-user daily Box Agent quota (reset daily at local midnight, allocated per user and not shared) and by the organisation's AI Unit allotment for chargeable modes; when a user exhausts the daily quota they are automatically transitioned to Box Agent Lite, a simplified Box AI experience, across AI Home, Documents, Notes and Hubs until the quota resets. Only Account Admins can see AI Unit consumption, through the Admin Console insights card (approximately 2-hour data lag) and a downloadable historical AI units report filterable by date, user and AI capability. Box AI Studio configuration of Custom Agents (instructions, knowledge, suggested prompts, availability, model, Pro and Expanded mode) is a separate control surface belonging to the existing Custom Agents record, not to Box Agent. Box's guardrails feature, which constrains where an action may run and which internal and external users it may involve, is documented as currently available only for Box Automate outcomes, with guardrails for Box AI Studio agent actions and MCP tools described as coming soon.
- Default state
- Conditional
- Availability
- Box states that the Box Agent and Box AI Home are available now for Enterprise Plus and Enterprise Advanced customers, and that Box AI Studio is available for Enterprise Advanced customers. Current Box AI usage documentation describes the Enterprise Plus entitlement as the integrated Box Agent (UI-driven, multi-step task execution) with multi-file Box AI Q&A and 2,000 included AI Units per month, and the Enterprise Advanced entitlement as Box Agent in Pro Mode with Box AI Studio and metadata extraction and 20,000 included AI Units per month. Availability of the capability to an individual user also depends on the organisation having Box AI provisioned and enabled and on the admin's AI Home access configuration. Box Agent Lite is the documented fallback experience after a user's daily quota is consumed.
- Licensing
- Box Agent in Standard Mode, and Pro Mode when run interactively by a user in the Box Web App, are documented as included in plan and as not deducting from the monthly AI Unit pool, while remaining subject to the daily Box Agent quota. Chargeable usage against AI Units includes Expanded Mode, the Box Agent via API, and automated or at-scale use such as Box Automate, Box Extract, Box AI APIs, MCP server AI workflows and CLI AI workflows. Included AI Units are allocated per entitlement period and do not roll over. Box directs pricing questions to a Box account executive or the Box pricing page; no pricing is recorded here.
- External model or provider
- Not established for the default Box Agent. Box documents model choice for Custom Agents in Box AI Studio, including Gemini, ChatGPT and Claude, and states that choosing your own model is available only to Enterprise Advanced customers. For a Box AI session Box states that, as part of processing a query, Box can choose the best available model from the list of enabled models, while the final generated answer always uses the user-selected model; models are labelled Standard or Premium in the Admin Console and AI Studio, and the Auto configuration defaults to a Standard model tier. Box does not identify a specific fixed model or provider for a default Box Agent run in the documentation reviewed, and the AI Studio model list is not attributed to Box Agent here.
- Limitations and uncertainty
- ESTABLISHED: Box Agent plans, searches user-accessible Box content, works across multiple documents, extracts and analyses information, selects capabilities, can invoke a Custom Agent, maintains persistent AI Home sessions, and returns synthesised outputs in the conversation. Content search follows the requesting user's existing permissions and collaboration settings. NOT ESTABLISHED: this record does not classify Box Agent as taking persistent operational action. Box's language of autonomous execution and multi-step task execution describes planning, reasoning and producing a deliverable; the documentation reviewed does not positively establish that Box Agent itself creates or uploads Box files, edits or deletes existing content, changes metadata, moves content, adds collaborators or starts workflows. Saving an output is documented as a user action (Copy, Save as Note, Add to Note). Because no persistent operational action is established for Box Agent itself, no approval gate for such actions is established either, and human confirmation is recorded as not established rather than as an approval model being asserted or denied. External action capability is recorded as unknown: external retrieval or the availability of other Box products is not evidence that Box Agent performs consequential operations in an external system, and the external behaviour of Box Automate, Box for Agentforce, the Box AI Agent in Microsoft 365 Copilot and the Box AI APIs is not attributed to Box Agent. Permission basis is recorded as user_permissions on the strength of explicit read and search evidence; authority to modify content is not separately established, and that distinction is deliberate. Operating modes affect reasoning depth, query capacity and context limits, and Pro and Expanded modes carry plan restrictions; nothing in the documentation reviewed indicates that a mode grants additional operational authority. Default state is recorded as conditional: Box AI must first be provisioned and enabled for the organisation and the tier must be Enterprise Plus or Enterprise Advanced, after which the documented Box AI for AI Home setting is enable for all managed users (Default); Box does not otherwise establish a capability-level operational default for Box Agent. Model and provider for the default agent are not established. Box's guardrails for agent actions and MCP tools are documented as coming soon and are not in force for this capability today. General Box AI limitations apply, including mixed accuracy on calculations, table structures, numbers and counting, document metadata such as page number, author, file size and collaborators, embedded images and charts within text documents, video and audio, and lower quality in non-English languages.
Evidence
- Introducing the New Box Agent (Apr 2026)
Supports: General · Function · Availability · Limitations · Primary source
Box AI Home is described as a full-screen conversational interface where the Box Agent operates, with persistent sessions allowing users to return to work in progress.
Box describes the Box Agent as employing an agentic loop with upfront planning and a visible to-do list, capability selection including searching an entire drive, extracting data points or invoking a Custom Agent, agent-to-human collaboration through adding and previewing sources, and autonomous execution synthesising information into a final deliverable.
Box states the Box Agent and Box AI Home are available now for Enterprise Plus and Enterprise Advanced customers and that Box AI Studio is available for Enterprise Advanced customers.
Box describes Standard, Pro and Expanded modes as scaling reasoning complexity and query and context capacity; no additional operational authority is attributed to a mode.
- Accessing Box AI (Using Box AI)
Supports: Permission basis · Actions · Data access · External model · Default state · Admin controls · General · Primary source
Box states that after a request is submitted the Box Agent searches through all content accessible to the user through permissions and collaboration settings.
Documented Box Agent outputs are conversational: summarising content, researching files, analysing patterns and creating templates, drafts and outlines, with responses saved by the user via Copy; no persistent write operation by the Agent is documented on this page.
Sources can be added by dragging and dropping from a device or external drive, dragging from Recents or Collections, uploading, or @ mentioning a user or content; AI Home also allows adding files, folders and entire Hubs.
Box states that choosing your own model is available only to Enterprise Advanced customers, that Box can choose the best available model from the list of enabled models while processing a query, and that the final generated answer always uses the user-selected model.
Box states the Box AI Agent is selected by default when using AI Home, and that the list of available agents depends on what the admin has enabled for the organisation.
Box's troubleshooting guidance directs users to confirm with an admin that the organisation is provisioned for Box AI, that AI Home is enabled, and that the tier supports the Pro toggle.
Pro Mode is enabled by a toggle in the prompt entry box and makes the agent use deeper reasoning, create more robust plans and execute tasks with increased reasoning capacity, with longer response times.
- Box AI Basics
Supports: Function · Actions · Limitations · Data access · Primary source
Box AI Home is documented as the full-page workspace with session history, source addition, agent selection including custom agents, and the prompt library and agent gallery; the same AI agent experience is shared across Preview, Notes, Hubs and Files.
Response actions listed by Box are Copy, Save as Note, Feedback and Citations, and in Notes Add to Note inserts AI-generated content; these are user-initiated actions on a generated response.
Box lists known limitations including session history visible only in the AI Tab, a 2MB text content limit per file, a 1,000-character query limit, reduced quality in non-English languages and Hub file limits.
In Hubs the Hub content is the source and sources outside the current Hub cannot be added; in Preview the previewed file is automatically a source; in Notes the current Note is the source.
- About Box AI
Supports: Permission basis · Function · Primary source
Box states that Box AI respects all user permissions and enterprise security policies and that data does not train the models without explicit permission.
Box describes Box AI key capabilities as asking questions and getting answers, summarising content, generating new content and extracting metadata across documents, Notes, Hubs and metadata templates.
- Understanding Box AI Usage: Daily Quotas and AI Units
Supports: Availability · Licensing · Admin controls · Limitations · General · Primary source
Box's usage documentation lists the Enterprise Plus entitlement as the integrated Box Agent providing UI-driven multi-step task execution with 2,000 included AI Units per month, and Enterprise Advanced as Box Agent in Pro Mode with Box AI Studio and 20,000 included AI Units per month.
Box Agent in Standard Mode and interactive Pro Mode in the web app are in-plan and do not deduct AI Units, while Expanded Mode, the Box Agent via API and automated or at-scale use are chargeable; unused AI Units do not roll over.
A per-user daily Box Agent quota applies to in-plan usage, resets at local midnight and is not shared across users; only Account Admins can view AI Unit consumption, via an insights card with an approximate two-hour lag and a downloadable historical report.
When a user reaches the daily quota they are automatically transitioned to Box Agent Lite, a simplified Box AI experience, across AI Home, Documents, Notes and Hubs until the quota resets.
Box lists AI experiences that consume the organisation AI Unit allotment rather than the daily Box Agent quota: custom agents in Expanded Mode, Box Automate, Box Extract, Box AI APIs, MCP server AI workflows and CLI AI workflows.
- Configuring Box AI
Supports: Admin controls · Default state · General · Primary source
Admins enable Box AI from the Box AI section of the Admin Console Settings tab and set per-service access for AI Home, Preview, Notes, Hubs, Extract, the AI API, Official Box Integrations and Box AI Studio, after accepting the Box AI Product Addendum.
For Box AI for AI Home the documented configuration options are disable for all managed users, enable for all managed users (marked Default), enable for select users and groups, or enable for everyone except select users and groups.
Selecting specific users or groups is limited to 100 names or email addresses and 100 groups, and only groups whose Permission Setting is Admins Only can be selected.
- Creating and Configuring Agents
Supports: External model · Limitations · Human confirmation · Primary source
Box AI Studio agent creators choose the model an agent uses, selecting Auto or from the providers available in the organisation; this model selection belongs to Custom Agents, not to the default Box Agent.
Box AI Studio is documented as available only for Enterprise Advanced accounts, and Custom Agents are separately configured with details, custom instructions, knowledge, suggested prompts, availability and advanced model settings, which distinguishes them from the default Box Agent.
Box states that custom instructions cannot override human approval workflows, break safety policies enforced in code, access restricted data or classifications, or force tool execution where permissions block them; Box does not document an execution approval gate for the default Box Agent.
- Guardrails in Box AI
Supports: External actions · Actions · Primary source
Box documents guardrails constraining where an action can run and which managed and external users it can involve, and states that guardrails are currently available for Box Automate outcomes for Enterprise Advanced customers, with guardrails for Box AI Studio agent actions and MCP tools coming soon.
Box's action-level guardrail examples such as Delete File, Move File, Upload File, Add Collaborator and Send Notification are documented for Box Automate outcomes, not for the default Box Agent.
- Box AI for Documents
Supports: Data access · Limitations · General · Primary source
Multi-document querying is limited to 10 selected files and is available only on Enterprise Plus and above; Box AI pulls information only from the document loaded in preview when working in Preview.
Box lists mixed or inaccurate results for calculations, table structures and numbers, word counting, document metadata such as page number, author, file size and collaborators, embedded images and charts, video and audio, plus a 2MB text limit and image processing constraints.
Box documents agent selection in Preview, where the Agent dropdown shows Box (Default) and lists agents the admin has enabled for the organisation.