Box · Box AI Studio

Custom Agents

Custom agents created in Box AI Studio are reusable, named AI assistants configured with a description, custom instructions, attached Box knowledge (files and Hubs), up to four suggested prompts, availability across Box surfaces (AI Home, Files, Hubs), an AI Unit usage limit, and an AI model selection (Auto or a model enabled in the organisation), with Pro Mode enabled by default for higher thinking levels and advanced behaviours such as recursive reasoning and enhanced document or video analysis. Through the Box AI Studio API an agent is an ai_agent object with name, access_state, optional icon_reference, allowed_entities (users or groups) and per-mode configuration for ask, text_gen and extract. Box documents the agent runtime as answering questions, generating text and extracting metadata from Box content; Box does not document a Box AI Studio custom agent itself creating, modifying, moving, deleting or sharing Box content, and states that guardrails for Box AI Studio agent actions and MCP tools are "coming soon". Persistent results such as saving an AI response as a Note or inserting content into a Note are documented as user-invoked actions.

Recorded characteristics

Function
An authorised creator opens the AI Studio tab and selects New Agent. Required configuration is a Name; optional elements are Details (icon, name, description), Custom Instructions, Knowledge (specific files or Hubs bound to the agent, referenced with @mentions and priority rules), Suggested Prompts (up to four), Availability on Box (AI Home, Files, Hubs - expanding as the agent passes evaluation tests for increasingly complex knowledge configurations), Usage (Expanded Mode on by default with a default AI Unit maximum of 1,000) and Advanced settings (model: Auto or a provider enabled in the organisation; Pro Mode on by default). The saved agent then appears for selection by permitted users inside Box AI experiences: in AI Home users can select from available agents, including custom agents from Box AI Studio, and agent selection is also available in Preview sidebar and modal views. At runtime the agent answers questions, generates text and extracts metadata from the Box content in scope. Box documents custom instructions as able to set personality, tone, workflows, output formats and to direct the agent to favor certain tools when multiple are available, and as unable to override human approval workflows, break safety policies enforced in code, access restricted data or classifications, or force tool execution when permissions block them. Through the API the same object is created with POST /2.0/ai_agents and managed with GET, PUT and DELETE; Box notes that for new and upgraded (non-legacy) agents, API usage is not supported.
Data access
Documented grounding is Box content: files and Hubs attached to the agent as Knowledge, plus the sources of the invoking Box AI session (the previewed file, multi-document selections from Files, folders, Collections or search results, a Hub in Hub queries, or the current Note). Box states that Box AI pulls information only from the document loaded in preview for preview questions, and that in Hub queries you cannot add sources outside the current Hub. Documented multi-document behaviour is multi-file Q&A across selected documents and Hub-wide querying; Box does not document unlimited tenant-wide corpus access for custom agents. Documented limits include a 2MB text content limit per file, a 1,000-character query limit, 40,000 files per Hub and 10 million files across all Hubs in an organisation.
Actions
Generative only
External actions
Unknown
Human confirmation
Not established
Permission basis
User permissions
Administrative control
Admin Console > Box AI > Settings controls access per user and group for AI Home, Preview, Notes, Hubs, Extract, AI API and official Box integrations (limit of 100 names/email addresses and 100 groups when enabling for specific users). Box AI Studio requires AI Home to be enabled first (Box AI > Settings > Configure on AI Home > Enable). Co-admin access is granted per co-admin through Users & Groups > Role and Access Permissions > AI Studio. The Models tab lists every model with provider, tier, Pro Mode availability, compliance badges (FRD, FRC, IL2, IL4) and query usage, and admins enable or disable individual models; Box states disabling models currently impacts model selection for the Box Agent and custom agents. The AI Studio tab lists agents with Name, Access, Created By, Monthly Queries and Last Used, filterable by Access (Enabled, Enabled for selected, Disabled), with Edit, Duplicate and Delete options (deletion cannot be undone). Legacy agents can be upgraded; the upgraded agent is disabled by default and copies name, description and custom instructions with the model set to Auto. Guardrails (target, managed-user and external-user criteria) are currently available for Box Automate outcomes, and Box states guardrails for Box AI Studio agent actions and MCP tools are coming soon.
Default state
Conditional
Availability
Box AI Studio is documented as available only for Enterprise Advanced accounts. Agent availability within Box is configured per agent through Availability on Box (AI Home, Files, Hubs), expanding as the agent passes evaluation tests for increasingly complex knowledge configurations. Access to an agent is controlled by access_state (enabled, disabled, enabled for selected users) and allowed_entities (users or groups).
Licensing
Box AI Studio (Custom Agent creation) is listed by Box as a feature of the Enterprise Advanced plan, which includes 20,000 AI Units per month; Business and Business Plus have AI Units available for purchase, Enterprise includes 1,000 and Enterprise Plus 2,000. Box states unused AI Units do not roll over. Custom Agents in expanded mode are charged against AI Units; if expanded mode is turned off the usage is not charged against AI Units but the query limit is lower for simple tasks. The Box AI Studio API requires a platform application with the ai.readwrite (Manage AI) scope.
External model or provider
Model selection is per agent: Auto (Box optimises automatically) or a specific model from those enabled in the organisation. Box's supported-models catalogue lists core models (available by default) and customer-enabled models (requiring admin activation or a request to Box), across capability tiers Standard, Premium and Ultra, from providers including OpenAI, Google and Anthropic among others listed on that page. Box states that as part of processing a query Box can choose the best available model from the list of enabled models, but the final generated answer always uses the user-selected model. Box states that Box AI respects all user permissions and enterprise security policies and that customer data never trains the AI models without explicit permission.
Limitations and uncertainty
Runtime write authority is not established. Box documents the custom-agent runtime as question answering, text generation and metadata extraction, and does not document a Box AI Studio custom agent itself creating, modifying, moving, deleting or sharing Box files, editing metadata, creating tasks or comments, changing collaborators or triggering workflows. Box's guardrails article says guardrails for Box AI Studio agent actions and MCP tools are coming soon, which indicates agent actions are anticipated but does not establish what a custom agent can do today; this is recorded as unresolved rather than as an absence. Saving an agent configuration is a creator or administrative action and is not treated as runtime action authority. Response-level persistence (Copy, Save as Note, Add to Note, session history in AI Home) is documented as user-invoked, and Box stores AI session history for resumability. Permission basis rests on Box's statement that Box AI respects all user permissions and enterprise security policies; Box does not separately document whether content attached as Knowledge by an agent creator is readable by an invoking user who lacks access to it, nor whether a service or agent identity is used at runtime - this is unresolved. Whether custom agents can invoke Box MCP tools, Box Skills or deterministic Box API operations is not documented: Box Agent Skills are described as instruction sets for AI coding assistants, and the Box MCP server is described as a hosted endpoint letting external AI agents and apps search and use Box files over OAuth. Box documentation is also internally inconsistent about API invocation of custom agents: the admin article states API usage is not supported for new and upgraded agents, while the developer comparison table presents the ai_agent parameter as the Box AI API customisation path. External action capability is recorded as unknown: calling a third-party model provider for inference is not treated as an external operational action, and no other outbound action is documented. AI-specific observability is limited: Box documents an AI_SECURITY_DETECTION enterprise event generated when Box AI detects a potential security risk such as prompt injection (Box Agents only; legacy agents not scanned), and the AI Studio admin table shows Monthly Queries and Last Used, but a per-invocation AI audit trail covering prompts, responses and content accessed is not established. Box documents no numeric cap on the number of custom agents and no custom-instruction character limit. Box notes non-English languages may produce lower quality results and that session history is visible only in the AI Tab.

Evidence