Connectors›Documents›Box
Box
Available on requestRead-only access to allowlisted Box folders, so an agent can work from your documents without the ability to alter or share them.
- Proposed scope
- Read-only, allowlisted folders
- Credential held by
- You
- Certification
- Not yet certified
What the agent would be able to do
- Read files inside folders named in your profile.
- Read file metadata, version numbers and modification history.
What it explicitly cannot do
- Upload, edit, move or delete any file.
- Create or modify a sharing link.
- Read a folder not named in your profile.
Where the credential lives
The credential is issued to you and held by Claude on your own device or in your own cloud tenancy. Skoor never holds it, never proxies the connection, and is not a subprocessor you need to disclose to your clients.
We specify the configuration and verify it from the outside — the same relationship an auditor has to your books.
What lands in the log, and where
agent_idWhich agent acted, and under which profile versionfile_idEvery file opened, by ID and versionfolderThe allowlisted folder it was read fromtsUTC timestamp, from your system clockWritten to the store named in your profile — your SIEM, your log bucket, or your own database. Skoor reads it to compute your Agent Skoor and holds no copy.
Which standards govern this connector
These describe controls, not a compliance opinion. Whether your programme as a whole meets a standard is a judgement for your counsel.
What would trigger a re-score
- A folder appears outside the allowlist.
- Sharing scopes are added to the app grant.
Version and history
This connector has not been certified. Once it is, this section carries the rubric version, the date, and a link to the changelog entry that promoted it — so a claim on this page can always be checked.
See this scored against your own deployment.
The assessment establishes which connectors you already have in play, what they can reach today, and the gap between that and this page.
Book an assessment