Skip to main content

About Box

Iru uses OAuth 2.0 (authorization code) to read files, folders, users, groups, and enterprise metadata. The authorizing Box user must be able to see the content your audit program cares about - prefer admin-level visibility when you need org-wide evidence.

How It Works

Iru uses Box’s OAuth 2.0 authorization code grant. You sign in at Box through the wizard’s popup, review scopes, and approve access; Box returns a code that Iru exchanges for tokens used on subsequent REST calls.
DetailValue
CategoryCloud storage
AuthenticationOAuth 2.0
Typical plansBusiness or Enterprise (full API surface)
Scopes commonly include read access to files/folders plus enterprise administration where applicable - exact strings appear on Box’s consent screen. Official references: OAuth 2.0, Scopes, Developer docs.

Prerequisites

  • Browser popups allowed for your Iru domain.
  • A Box account with sufficient rights for the folders and users under review.

Connect Box to Iru

Complete this tab before you enable Box in Iru Compliance, so the right user is ready for OAuth.
1

Sign in to Box

Open box.com and sign in with the account you will use in the OAuth popup (prefer co-admin or admin visibility for org-wide evidence).
2

Confirm enterprise visibility

Browse Admin Console (or equivalent) and spot-check users, groups, and folders your audit program must cover. If this user cannot see an object in Box, Iru cannot read it either.
3

Review OAuth scopes

Skim Box’s OAuth 2.0 and Scopes docs so the consent screen matches your expectations.
4

Allow pop-ups for Iru

In the browser profile you will use for Compliance, allow pop-ups for your Iru hostname so the Box consent window is not blocked.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Re-authorize with a user who can access missing enterprise objects.
Access tokens are short-lived; Iru refreshes automatically - if refresh fails after 60 days idle or consent changes, re-authorize.

Considerations

Tokens are tied to the authorizing…

Tokens are tied to the authorizing user - deactivation may break sync until someone reconnects.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.