Box · Box AI

Box Agent

Box Agent is the default, general AI agent experience in Box AI. Box documents it as an agentic loop that plans a request into a visible to-do list, selects capabilities such as searching a drive, extracting data points or invoking a Custom Agent built in Box AI Studio, and synthesises a final deliverable in the conversation. It operates across Box AI Home, Preview, Notes and Hubs, searches content the requesting user can already access through permissions and collaboration settings, and is offered in Standard, Pro and Expanded modes. Box documentation reviewed for this record does not establish that Box Agent itself writes, moves or deletes Box content, changes metadata or starts workflows.

Recorded characteristics

Function
Box documents Box Agent as the default agent selected when using Box AI Home, and as the shared AI agent experience across Preview, Files (multi-document), Notes and Hubs. Box describes a default agentic loop with four documented elements: upfront planning, in which the Agent breaks complex goals into manageable steps and creates a visible to-do list of its reasoning; capability selection, in which it selects the appropriate tools, whether searching an entire drive, extracting data points, or invoking a Custom Agent built in Box AI Studio; agent-to-human collaboration, in which users add and preview sources within the flow of work; and autonomous execution, in which the Agent synthesises information into a final deliverable. On submission of a prompt the Box Agent searches all content accessible to the user through permissions and collaboration settings and returns a response the user can continue working on. Documented user-facing task types are summarising content, researching files, analysing patterns and creating templates, drafts and outlines. Box AI Home sessions are persistent, with session history that users can view and resume. Box describes the Enterprise Plus entitlement as the integrated Box Agent providing UI-driven, multi-step task execution. Box's own delivered outputs are returned in the conversation; saving them is a user action (Copy, Save as Note, or Add to Note in Box Notes). Box Agent is distinct from a Custom Agent created in Box AI Studio: a Custom Agent is a separately configured agent with its own instructions, knowledge, availability and model, and Box documents Box Agent as able to invoke a Custom Agent as one of its available capabilities; invoking a Custom Agent does not make every Custom Agent configuration part of this record. This record also excludes Box Extract, Box Automate, Box for Agentforce, the Box AI Agent in Microsoft 365 Copilot, the Box AI APIs and the Box MCP server.
Data access
Box documents Box Agent as searching all content accessible to the requesting user through existing permissions and collaboration settings; Box states more generally that Box AI respects all user permissions and enterprise security policies. Access is therefore user-scoped, not organisation-wide. Users can narrow or extend what the Agent uses by adding sources: dragging and dropping from a device or external drive, dragging from the left navigation (Recents or Collections), uploading from a device, or @ mentioning a user or content, and by adding files, folders or an entire Hub as sources. In Preview the previewed file is automatically a source; in a Hub the Hub's content is the source and sources outside the current Hub cannot be added; in Notes the current Note is the source. Where the Box Agent invokes a Custom Agent, that Custom Agent's own configured knowledge (files and Hubs attached in Box AI Studio) applies to that invocation. Documented content constraints include a 2MB text limit per file (larger files process only the first 2MB), a 10-file limit for multi-document queries, query character limits (1,000 characters for legacy agents; 64,000 characters for new agents), image handling at a maximum of 2048 x 2048 pixels and up to 10 pages for multi-page image formats, and Hub file limits. AI Home retains session history that users can resume, clear or permanently delete.
Actions
Generative only
External actions
Unknown
Human confirmation
Not established
Permission basis
User permissions
Administrative control
Box AI must first be provisioned and enabled for the organisation; an admin enables Box AI from the Box AI section of the Admin Console Settings tab, and must review and accept the Box AI Product Addendum before enabling, with some organisations shown a Review Agreement Offline message requiring contact with Box. Within the Box AI settings, admins configure access separately for AI Home, Preview, Notes, Hubs, Extract, the AI API and Official Box Integrations, and separately for Box AI Studio. For Box AI for AI Home the documented options are: disable for all managed users; enable for all managed users (marked Default); enable for select users and groups; or enable for everyone except select users and groups, with a documented limit of 100 names or email addresses and 100 groups, and group selection restricted to groups whose Permission Setting is Admins Only. The list of agents and models available to a user depends on what the admin has enabled for the organisation; choosing a model is available only to Enterprise Advanced. Consumption is governed by a per-user daily Box Agent quota (reset daily at local midnight, allocated per user and not shared) and by the organisation's AI Unit allotment for chargeable modes; when a user exhausts the daily quota they are automatically transitioned to Box Agent Lite, a simplified Box AI experience, across AI Home, Documents, Notes and Hubs until the quota resets. Only Account Admins can see AI Unit consumption, through the Admin Console insights card (approximately 2-hour data lag) and a downloadable historical AI units report filterable by date, user and AI capability. Box AI Studio configuration of Custom Agents (instructions, knowledge, suggested prompts, availability, model, Pro and Expanded mode) is a separate control surface belonging to the existing Custom Agents record, not to Box Agent. Box's guardrails feature, which constrains where an action may run and which internal and external users it may involve, is documented as currently available only for Box Automate outcomes, with guardrails for Box AI Studio agent actions and MCP tools described as coming soon.
Default state
Conditional
Availability
Box states that the Box Agent and Box AI Home are available now for Enterprise Plus and Enterprise Advanced customers, and that Box AI Studio is available for Enterprise Advanced customers. Current Box AI usage documentation describes the Enterprise Plus entitlement as the integrated Box Agent (UI-driven, multi-step task execution) with multi-file Box AI Q&A and 2,000 included AI Units per month, and the Enterprise Advanced entitlement as Box Agent in Pro Mode with Box AI Studio and metadata extraction and 20,000 included AI Units per month. Availability of the capability to an individual user also depends on the organisation having Box AI provisioned and enabled and on the admin's AI Home access configuration. Box Agent Lite is the documented fallback experience after a user's daily quota is consumed.
Licensing
Box Agent in Standard Mode, and Pro Mode when run interactively by a user in the Box Web App, are documented as included in plan and as not deducting from the monthly AI Unit pool, while remaining subject to the daily Box Agent quota. Chargeable usage against AI Units includes Expanded Mode, the Box Agent via API, and automated or at-scale use such as Box Automate, Box Extract, Box AI APIs, MCP server AI workflows and CLI AI workflows. Included AI Units are allocated per entitlement period and do not roll over. Box directs pricing questions to a Box account executive or the Box pricing page; no pricing is recorded here.
External model or provider
Not established for the default Box Agent. Box documents model choice for Custom Agents in Box AI Studio, including Gemini, ChatGPT and Claude, and states that choosing your own model is available only to Enterprise Advanced customers. For a Box AI session Box states that, as part of processing a query, Box can choose the best available model from the list of enabled models, while the final generated answer always uses the user-selected model; models are labelled Standard or Premium in the Admin Console and AI Studio, and the Auto configuration defaults to a Standard model tier. Box does not identify a specific fixed model or provider for a default Box Agent run in the documentation reviewed, and the AI Studio model list is not attributed to Box Agent here.
Limitations and uncertainty
ESTABLISHED: Box Agent plans, searches user-accessible Box content, works across multiple documents, extracts and analyses information, selects capabilities, can invoke a Custom Agent, maintains persistent AI Home sessions, and returns synthesised outputs in the conversation. Content search follows the requesting user's existing permissions and collaboration settings. NOT ESTABLISHED: this record does not classify Box Agent as taking persistent operational action. Box's language of autonomous execution and multi-step task execution describes planning, reasoning and producing a deliverable; the documentation reviewed does not positively establish that Box Agent itself creates or uploads Box files, edits or deletes existing content, changes metadata, moves content, adds collaborators or starts workflows. Saving an output is documented as a user action (Copy, Save as Note, Add to Note). Because no persistent operational action is established for Box Agent itself, no approval gate for such actions is established either, and human confirmation is recorded as not established rather than as an approval model being asserted or denied. External action capability is recorded as unknown: external retrieval or the availability of other Box products is not evidence that Box Agent performs consequential operations in an external system, and the external behaviour of Box Automate, Box for Agentforce, the Box AI Agent in Microsoft 365 Copilot and the Box AI APIs is not attributed to Box Agent. Permission basis is recorded as user_permissions on the strength of explicit read and search evidence; authority to modify content is not separately established, and that distinction is deliberate. Operating modes affect reasoning depth, query capacity and context limits, and Pro and Expanded modes carry plan restrictions; nothing in the documentation reviewed indicates that a mode grants additional operational authority. Default state is recorded as conditional: Box AI must first be provisioned and enabled for the organisation and the tier must be Enterprise Plus or Enterprise Advanced, after which the documented Box AI for AI Home setting is enable for all managed users (Default); Box does not otherwise establish a capability-level operational default for Box Agent. Model and provider for the default agent are not established. Box's guardrails for agent actions and MCP tools are documented as coming soon and are not in force for this capability today. General Box AI limitations apply, including mixed accuracy on calculations, table structures, numbers and counting, document metadata such as page number, author, file size and collaborators, embedded images and charts within text documents, video and audio, and lower quality in non-English languages.

Evidence