Content & Sharing settings allow you to enable or disable various permission types that are available to managed user when collaborating and sharing files. This topic contains the following sections:
- Shared Links
- Custom Shared Links
- Collaborating on Content
- Watermarking
- Content Creation
- File Request
- Relay
- Cascading Folder Level Metadata
- Auto-Expiration
- Trash
Shared Links
The Shared Links section is where you configure shared link settings and permissions for content owned by managed users.
Setting | Description |
---|---|
Allow shared links for |
Defines the content type you allow to be shared. Select from:
|
Definition of company |
When selecting settings that define "people in your company," defines what "in your company" means. Select from:
Admins for enterprises with multiple companies sharing one email domain will have created at least one custom subdomain. But other large enterprises instead may have multiple companies that each with a separate EID. To make links shared with “people in your company” available only on a per-company basis, and not across your entire organization, select Enterprise ID. Important If you change your company definition value from Users with Email Domain to Enterprise ID, links previously shared with “people in the company” become inaccessible to people from companies with different EIDs. Similarly, people from one company who used to share with people from other companies no longer can do so. |
People who can access shared links |
Defines what access options are available for the content types selected above. By default, all options are enabled, meaning that anyone with appropriate permissions can choose, per item, what access permission to grant their content. Select from:
Changing this setting alters what types of new shared links can be created for content owned by your enterprise. Existing shared links are also affected by this setting, meaning that previously created shared links with broader access are lowered to the restrictive setting. For example, if you change this setting from people with the link to something more restrictive, your managed users can no longer create open shared links. Further, any pre-existing open shared links would be changed to people in your company. If you change this setting from a less restrictive setting to a more restrictive setting and then back again, shared links created before the setting changes retain their type. |
Default access for shared links |
Defines the default access level of newly-created shared links. If you have limited the access options in an earlier setting, your options here are limited accordingly.
|
Shared Link Permission |
Defines the allowed and default permissions for file, folder, and Box Notes shared links. For files, folders, and Box Notes, you define both the maximum permission allowed and the default permission when users share links, and you select from the following values for each:
For each part of these options:
|
Custom Shared Links
Custom URLs enable people to customize the URLs for created shared links. This applies to content you want to be readily accessible to large groups of people (externally or internally) using a customized URL that is easy to remember. If you make this link available as people with the link, the linked folder or file is publicly accessible. Custom URLs are appropriate for public-facing materials such as product documentation or marketing materials and are not intended for the secure sharing of sensitive content.
Setting | Definition |
---|---|
Allow custom shared link URLs for links with public access |
Select the check box to enable the custom URL feature for open public sharing. Example of a custom link: https://.box.com/v/custom-public-link Clear the check box to block the creation of custom URLs in your enterprise. If you disable this option, you break any existing custom URLs with people with the link security. However, if you later re-enable public custom URLs, those same pre-existing links again become valid. This setting does not apply to custom URLs with company and collaborators-only security levels. The default state is cleared. |
Show your custom domain in shared link URLs |
Select the check box to enable your custom domain display in shared link URLs. The default state is selected. |
Collaborating on Content
This section is where you select the roles/permissions you want to allow folder owners to choose from when collaborating on items and define other collaboration settings
Setting | Description |
---|---|
Available Roles |
Determines which roles can be chosen for collaborators. Roles selected here will be available to choose from when setting access privileges for collaborators. Each role provides different access privileges. The default states are selected for all roles. |
Default collaboration roles |
Determines the default access level across your entire organization for files people share. Select from:
Note Users are allowed to change this setting when they invite collaborators. |
Restrict invites |
Determines who can invite collaborators. Select this option so only folder Owners and Co-owners and Admins (including Co-admins and Group Admins) can invite collaborators to a given folder. The default state is cleared. |
Enable invite links |
Determines whether people can use invite links to collaborate. Invite links grant collaborator access to a folder to people who click the link. If these links are disabled, users will still be able to invite collaborators through email invites sent securely by Box. Unless accepted, pending collaboration invitations expire after 30 days. The default state is selected. |
Enable group invites |
Determines whether users can invite groups to collaborate in folders. Enabling group invites allows collaborators with editor, co-owner, or owner permissions to invite group collaborators and modify their permissions on those items. The default state is selected. |
Restrict Ownership Transfer |
Determines whether non-admins can transfer ownership of a file or folder to external collaborators and move a file or folder owned by your enterprise to a folder owned by an external account. Select this option to prevent ownership transfer of a file or folder to external collaborators. Admin and co-admins of your account will still be able to transfer ownership to external collaborators. The default state is cleared. |
External collaboration | Determines whether your users can collaborate with any external collaborators (default) or only external collaborators in allowlisted domains. See Limit collaboration to allowlisted domains for details. |
Watermarking
Watermarking places a semi-transparent overlay of the current viewer's name and time of access across a document's contents to deter unauthorized sharing. When your Box users choose to add a watermark to shared files, you can determine whether the watermarks on all files will be rasterized, or whether watermarks will be vector-based or rasterized, depending on the file type.
Setting | Description |
---|---|
Watermarking |
Determines how watermarking will be applied to different file types. Select:
|
Watermarking Differences
The different types of watermarking have differences that may affect your decision about which one to use.
Vector-based | Raster | |
---|---|---|
Resolution |
Infinite; the watermark scales when viewers zoom in or out |
Limited to 2048 x 2048 pixels; the watermark does not scale when zooming |
Text copying | Yes | No |
Text searching | Yes | No |
Links | Clickable | Not clickable |
Modifies underlying content | No | Yes |
Watermarked document size | Smaller | Larger |
Document security | Medium | High |
Watermarking Use Cases
Use the Vector-based and rasterized watermarking option:
- When dealing with large files that need to maintain readability, documents such as blueprints, diagrams, or files containing a lot of small print.
- When dealing with text-based files where text needs to be copied and searched for or when hyperlinks need to be clickable.
- When you have storage or bandwidth concerns with the size of watermarked files being shared.
Use the Rasterized watermarking only option:
- When you want to lock down the watermarked file by not allowing any text to be copied.
- When the content in question is of the highest sensitivity level. Note that while watermarking is a security deterrent, a very motivated and technically adept hacker can remove a vector watermark. Doing this will impact the original formatting of the underlying document. This is slightly different from a Rasterized watermark where you cannot remove the watermark without destroying the underlying content as well.
Content Creation
This section allows you to restrict certain types of content creation. Higher restrictions will provide admins greater control over the content and structure. However, users will be more restricted in creating content, which may impact the amount of collaboration.
Setting | Description |
---|---|
Restrict content creation |
Determines who can create and delete folders, files, and bookmarks at the root level of your Box instance. Select this option to prevent all non-admin managed users from creating, deleting, and moving folders in their "All Files" section. Enable this setting to create the folder structure for the entire account and then invite users into this structure. Note If Restrict content creation is enabled, admins can transfer ownership of folders to managed users, but managed users cannot transfer ownership to others. The default state is cleared. |
Restrict tag creation |
Cleared by default. Determines who can create tags for files in your account. Tags can be used by users to easily label and search for content. Select this option to limit tag creation, and then select who can create tags from:
|
Email Uploads |
Determines whether you to allow people to upload file attachments to a specific Box folder via email. The default state is cleared. |
File Request
File Request enables users to request files and metadata from anyone via a link
Setting | Description |
---|---|
File request users |
Defines who can request files. Click Configure Users and then select:
Note
|
File request permissions |
Defines what folder owner roles are allowed to make file requests. Click Configure Permissions and then select:
|
File Request Link Access |
Defines whether file uploaders are required to sign in with a Box account. When selected, this setting:
The default state is cleared. |
Relay
Relay allows users to build workflows to automate tasks and content actions within Box. If enabled, your users will be able to build automated workflows on folders they own or co-own.
Setting | Description |
---|---|
Relay users |
Defines who can use Relay. Click Edit Configuration and then select:
Note
|
Relay permissions |
Defines who can define and launch workflows from folders the own, co-own, or can edit. Click Edit Configuration and then select:
Note If you change the setting to the more restrictive configuration (Owners/co-owners), existing active workflows created by an editor continue to run as expected and continue to display in the Workflows page. If you want to deactivate them, you can do so in your Relay Admin Console view. |
Template publication permissions |
Defines who can publish workflow templates. Click Edit Configuration and then select:
Note
|
Cascading Folder Level Metadata
Cascading Folder Level Metadata enables users to cascade a metadata template and its attribute values to new or existing folder contents. To be granted Cascade permissions via this setting, users must have permission to edit the folder-level metadata.
Setting | Description |
---|---|
Cascading folder level metadata permissions |
Defines who can can create cascade policies. Click Configure and then select:
Note If you enable for select users or all users except selected, you can enter up to 100 managed users' user names or email addresses. |
Auto-Expiration
This is where you define default expiration for shared links and invited collaborators.
Trash
Enabling trash will provide each of your users their own trash folder. This is recommended so users can retrieve items they may have accidentally deleted.
Setting | Description |
---|---|
Enable Trash |
Determines whether Trash is used in your organization. The default state is selected. |
People who can permanently delete content in Trash |
Available only if Enable Trash is selected. Determines who can permanently delete content once it has been sent to Trash. Select from:
The ability to choose who can permanently delete content in the trash is only available as part of the Box Governance package. |
Items in trash are automatically deleted after |
This setting is available only if Enable Trash is selected. Determines how long content is in Trash of your managed users' accounts before it is permanently deleted. After the specified time period passes, the items are permanently deleted. If you modify this setting, the new duration does not apply retroactively to items already in the trash. Select from:
Retention set by retention policies override this setting for any content managed by those retention policies. |