Box external sharing review board for IT and compliance

By General Input

One risk ranked table of every active Box share link and outside collaborator, with revoke, tighten and downgrade buttons built into every row.

Integrations

  • Box
  • Slack Bot

Type

App

Categories

  • Operations

Build me a Box external exposure review board. Our IT lead or compliance lead opens it every week to answer one question: what content of ours can someone outside the company reach right now? The whole app is built around one risk ranked table covering every active shared link and every external collaborator across the folders I choose to scan, and every row in that table is fixable without leaving the page.

Start with a short scan setup the reviewer controls: which Box folders are in scope, how many levels deep to walk, our own company email domains so external people can be identified, and the date our admin enabled automatic link expiration. Save these settings so the next review pass starts from the same scope instead of being reconfigured every week.

To build the table, handlers walk the selected folders with Box List Folder Items, recursing into subfolders up to the configured depth, and use Box Search Content to catch sensitive named files that sit outside the picked folders. For every file found, read its sharing state with Box Get File Information, requesting the shared link fields so we can see the access level, whether a password is set, whether an expiration date exists, and whether downloading is allowed. Get Shared Link for File and Get Shared Link for Folder work here too. For each folder, call Box List Folder Collaborations to find who has access, and use Box List File Collaborations for file level access, then flag any collaborator whose email domain is not one of ours.

Score every row so the worst exposure floats to the top. Add risk for a link set to open access, meaning anyone with the link can view it. Add risk when no expiration date is set, when no password is set, and when download is enabled. Add risk when the file or folder name contains sensitive words such as invoice, contract, salary, passport, payroll, offer, tax, NDA or bank. Add risk for external collaborators, weighted by their role, so an outside editor or co-owner outranks an outside viewer. Show the score as a clear high, medium or low band with the contributing reasons listed on the row, not just a bare number, because the reviewer needs to know why something surfaced.

The main surface is that single table, sorted by risk, with the item name, its folder path, the type of exposure (shared link or external collaborator), who the external person is when applicable, the access level, expiry, password and download state, and the risk reasons. Give it filters for exposure type, risk band, folder, and external domain. One filter matters more than the rest and should be a first class toggle: legacy links. Box's own automatic expiration setting is not retroactive, so links created before an admin switched it on never expire and nobody remembers creating them. Define a legacy link as one with no expiration date on an item created before the enablement date the reviewer entered, and let them isolate exactly those rows in one click.

Every row is actionable. Remove a link outright with Box Remove Shared Link from File or Box Remove Shared Link from Folder. Reissue a link safely with Box Add Shared Link to File or Box Add Shared Link to Folder, setting it to company only access with an expiration date and a password, using defaults the reviewer configured but allowing them to override per row. Downgrade an external person to viewer with Box Update Collaboration, or revoke their access entirely with Box Remove Collaboration. Support multi select with checkboxes and a bulk action bar so a reviewer can select twenty legacy links and revoke or tighten them in one batch, with a confirmation step showing exactly what is about to change and a per item result afterwards so partial failures are visible instead of silent.

Persist a reviewer log. Every time someone acts on an item, or marks it as reviewed and accepted with a short note explaining why the exposure is fine, store the item, the decision, the reviewer and the timestamp. Show a reviewed state on the row and let the reviewer filter to what is still unreviewed in the current pass, so a large scan can be worked through across sittings. This log is what makes the board double as audit evidence at renewal or certification time, so make it exportable and keep history rather than overwriting the last decision.

When the reviewer finishes a pass, a button posts a recap to Slack with Send a Message to the channel they choose. The recap covers how many links were revoked, how many were tightened with a password or expiry, how many external collaborators were downgraded or removed, how many legacy links were cleared, and what is still open and carrying high risk, with the reviewer's name and the date of the pass.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them