About Box
Iru uses OAuth 2.0 (authorization code) to read files, folders, users, groups, and enterprise metadata. The authorizing Box user must be able to see the content your audit program cares about - prefer admin-level visibility when you need org-wide evidence.How It Works
Iru uses Box’s OAuth 2.0 authorization code grant. You sign in at Box through the wizard’s popup, review scopes, and approve access; Box returns a code that Iru exchanges for tokens used on subsequent REST calls.| Detail | Value |
|---|---|
| Category | Cloud storage |
| Authentication | OAuth 2.0 |
| Typical plans | Business or Enterprise (full API surface) |
Prerequisites
- Browser popups allowed for your Iru domain.
- A Box account with sufficient rights for the folders and users under review.
Connect Box to Iru
- Box
- Iru Compliance
Complete this tab before you enable Box in Iru Compliance, so the right user is ready for OAuth.
Sign in to Box
Open box.com and sign in with the account you will use in the OAuth popup (prefer co-admin or admin visibility for org-wide evidence).
Confirm enterprise visibility
Browse Admin Console (or equivalent) and spot-check users, groups, and folders your audit program must cover. If this user cannot see an object in Box, Iru cannot read it either.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
Popup blocked
Popup blocked
Allow popups; toggle source off/on.
Insufficient permissions
Insufficient permissions
Re-authorize with a user who can access missing enterprise objects.
Stale refresh
Stale refresh
Access tokens are short-lived; Iru refreshes automatically - if refresh fails after 60 days idle or consent changes, re-authorize.
Considerations
Tokens are tied to the authorizing…
Tokens are tied to the authorizing user - deactivation may break sync until someone reconnects.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
