Box external sharing review board for IT and compliance
One risk ranked table of every active Box share link and outside collaborator, with revoke, tighten and downgrade buttons built into every row.
Build me a Box external exposure review board. Our IT lead or compliance lead opens it every week to answer one question: what content of ours can someone outside the company reach right now? The whole app is built around one risk ranked table covering every active shared link and every external collaborator across the folders I choose to scan, and every row in that table is fixable without leaving the page.
Start with a short scan setup the reviewer controls: which Box folders are in scope, how many levels deep to walk, our own company email domains so external people can be identified, and the date our admin enabled automatic link expiration. Save these settings so the next review pass starts from the same scope instead of being reconfigured every week.
To build the table, handlers walk the selected folders with Box List Folder Items, recursing into subfolders up to the configured depth, and use Box Search Content to catch sensitive named files that sit outside the picked folders. For every file found, read its sharing state with Box Get File Information, requesting the shared link fields so we can see the access level, whether a password is set, whether an expiration date exists, and whether downloading is allowed. Get Shared Link for File and Get Shared Link for Folder work here too. For each folder, call Box List Folder Collaborations to find who has access, and use Box List File Collaborations for file level access, then flag any collaborator whose email domain is not one of ours.
Score every row so the worst exposure floats to the top. Add risk for a link set to open access, meaning anyone with the link can view it. Add risk when no expiration date is set, when no password is set, and when download is enabled. Add risk when the file or folder name contains sensitive words such as invoice, contract, salary, passport, payroll, offer, tax, NDA or bank. Add risk for external collaborators, weighted by their role, so an outside editor or co-owner outranks an outside viewer. Show the score as a clear high, medium or low band with the contributing reasons listed on the row, not just a bare number, because the reviewer needs to know why something surfaced.
The main surface is that single table, sorted by risk, with the item name, its folder path, the type of exposure (shared link or external collaborator), who the external person is when applicable, the access level, expiry, password and download state, and the risk reasons. Give it filters for exposure type, risk band, folder, and external domain. One filter matters more than the rest and should be a first class toggle: legacy links. Box's own automatic expiration setting is not retroactive, so links created before an admin switched it on never expire and nobody remembers creating them. Define a legacy link as one with no expiration date on an item created before the enablement date the reviewer entered, and let them isolate exactly those rows in one click.
Every row is actionable. Remove a link outright with Box Remove Shared Link from File or Box Remove Shared Link from Folder. Reissue a link safely with Box Add Shared Link to File or Box Add Shared Link to Folder, setting it to company only access with an expiration date and a password, using defaults the reviewer configured but allowing them to override per row. Downgrade an external person to viewer with Box Update Collaboration, or revoke their access entirely with Box Remove Collaboration. Support multi select with checkboxes and a bulk action bar so a reviewer can select twenty legacy links and revoke or tighten them in one batch, with a confirmation step showing exactly what is about to change and a per item result afterwards so partial failures are visible instead of silent.
Persist a reviewer log. Every time someone acts on an item, or marks it as reviewed and accepted with a short note explaining why the exposure is fine, store the item, the decision, the reviewer and the timestamp. Show a reviewed state on the row and let the reviewer filter to what is still unreviewed in the current pass, so a large scan can be worked through across sittings. This log is what makes the board double as audit evidence at renewal or certification time, so make it exportable and keep history rather than overwriting the last decision.
When the reviewer finishes a pass, a button posts a recap to Slack with Send a Message to the channel they choose. The recap covers how many links were revoked, how many were tightened with a password or expiry, how many external collaborators were downgraded or removed, how many legacy links were cleared, and what is still open and carrying high risk, with the reviewer's name and the date of the pass.
What does this prompt do?
- Scans the Box folders you pick and builds one risk ranked table answering a single question: what content of ours can someone outside the company reach right now?
- Scores every row on what actually creates exposure, including links open to anyone, no expiry date set, no password, downloads allowed, and sensitive words in the file name such as invoice, contract, salary, passport or payroll.
- Fixes each row in place without leaving the page. Kill a link outright, reissue it as company only with a password and an expiration date, downgrade an outside collaborator to view only, or revoke them entirely. Multi select rows and act on the whole batch at once.
- Calls out legacy links created before your admin switched on automatic expiration, since that setting was never applied to them, and records who reviewed each item and when so the board doubles as audit evidence.
What do I need to use this?
- A Box account with permission to view and change sharing on the folders you want to review
- The list of folders that should be in scope, plus your company email domain so people outside the business are easy to spot
- The approximate date your admin turned on automatic link expiration, if you have it, so pre existing links can be flagged separately
- A Slack workspace and channel if you want the end of pass recap posted for the team
How can I customize it?
- Change which folders are in scope, how deep the scan walks, and whether it also sweeps for sensitive file names across your whole account
- Edit the sensitive word list and adjust how many points each risk factor adds, so the ranking matches how your business actually thinks about exposure
- Set the default access level, password rule and expiry window used when reissuing a link, and pick the Slack channel that receives the recap
FAQs
My admin already turned on automatic link expiration. Do I still need this?
Can I fix problems from inside the board, or does it only report?
How does it decide who counts as external?
Will it change anything in Box on its own?
Can I use this as evidence in an audit or certification?
Related templates
See how your brand's news coverage and sentiment stack up against four competitors, then let an assistant write the weekly report for you.
One screen showing every social post waiting on approval, sorted by deadline, so reviewers can approve or reject without leaving the page.
Every Monday, find the past champions and closed-won contacts who changed jobs, update Attio, and get the moves worth chasing in Slack.
Staff submit what happened, your social manager edits the copy, picks the accounts and puts it on the calendar without a single spreadsheet.
Open one board each morning, see which voice calls went badly, replay the exact moment the caller got frustrated, and file the fix.
A personal queue of every overdue Guru card, sorted by how late it is, with one-click verify, reassign, comment, and an agent that drafts the refresh for you.
Stop guessing who outside your company can open your files.
Open one board, see every live share link and outside collaborator ranked by risk, and close the dangerous ones before your next audit does it for you.