Box

Pull enterprise users and groups from Box using a developer token.

Source connector

Source connector — pulls identity and access data from Box into ComplianceScout where it is scored against your compliance frameworks and violation rules.

What ComplianceScout collects

After a successful sync, the following data is available in your ComplianceScout dashboard for violation detection and reporting.

  • All enterprise users with email, name, login, status, and storage quota
  • Group memberships and user roles within groups
  • Admin and co-admin designations

Required credentials

These fields are collected when you add the connector in the ComplianceScout dashboard. Secrets are encrypted at rest using AES-256-GCM and are never logged.

FieldTypeRequiredNotes
Developer tokenSecretRequiredGenerate from the Box Developer Console. The token user must have admin access to list all users.
Enterprise ID (optional)TextOptionalOptional. Your Box Enterprise ID for labelling purposes.

How to set up this connector

Follow these steps to gather the credentials above and connect Box to ComplianceScout.

  1. Go to the Box Developer Console (developer.box.com) and sign in as an admin.

  2. Create a new Custom App with Server Authentication (OAuth 2.0 with client credentials).

  3. Under Configuration, generate a Developer Token for testing or obtain a long-lived token via the OAuth flow.

  4. Submit the app for admin approval in your Box Admin Console → Custom Apps.

  5. In ComplianceScout, go to Data & Secrets → Integrations → Add Connector → Box and enter the developer token.

Ready to connect Box?

Start a free trial — your tenant is provisioned instantly and you can wire up this integration from the connectors page.