As AI agents take on real work inside the enterprise, the question isn't just what they can read. It's what they can do. A custom agent that can upload, move, or share content on behalf of a user needs clear rules about where it can act and who it can involve. Agent Guardrails give admins and agent builders a new layer of control in Box AI, so every custom agent operates within the boundaries your organization sets.
Agent Guardrails apply to Box custom agents built in AI Studio. They set the operational boundaries in which an agent can act.
What's new
Agent Guardrails are available in two places, giving you both enterprise-wide defaults and per-agent flexibility.
- Enterprise defaults in AI Studio
Admins can now set default guardrails for all custom agents from Admin Console > Box AI > Security. These defaults apply to every new custom agent at the time of creation, so agent builders start from a safe baseline instead of a blank slate.
- Following are the actions for which guardrails can currently be configured. As Box custom agents gain additional capabilities, more guardrails will be introduced for high-risk actions:
- Upload file
- Upload file version
- Create Box Note
For each action, admins can configure three types of guardrail constraints:
- Target Criteria: define where the action can be taken.
- Choose no restrictions,
- Specific items only (allowlist by Shield classification label), or
All items with exceptions (denylist by classification label).
Under all items with exceptions, admins can also turn on 'Don't allow on any externally accessible items' to prevent actions against any location that is shared publicly, accessible to external collaborators, or owned by an external organization.
Note: Enterprise defaults apply to new agents going forward. They don't retroactively change guardrails on agents that already exist. To use classification-based criteria, your organization must first have Shield Classification Labels configured.
- Per-agent configuration in AI Studio
When you create or edit a custom agent in AI Studio, you can configure guardrails for each action that agent can take. This is where you tailor an agent to its job.
- A Planning agent can be restricted from creating a Box Note in a folder that has a public shared link.
- A Social Media agent can be blocked from editing files with a Confidential classification label.
- A Finance agent can be blocked from creating files outside a specific project folder.
For each action, agent creators can modify the enterprise default guardrails set by the admin.