At Cisco, onboarding a new customer used to include 30–45 minutes of copying and pasting data between systems. Frank Murphy and his team have now automated much of that work—saving countless hours of manual data entry. The mechanism matters. By connecting content in Box with Cisco systems through MCP, the team can put governed enterprise data to work without creating another manual handoff or moving sensitive content into a new storage environment. Frank calls this “compute-in-place”: analyzing business content where it already resides, rather than lifting and shifting it elsewhere. For Cisco’s customer success team, that means the people closest to the customer can investigate problems, improve workflows, and build solutions without waiting for every idea to move through a development queue. The architecture lesson for IT leaders: Enterprise AI doesn’t always require moving more data. Sometimes the better approach is to make the content you already govern computable where it lives.
Box
Technology, Information and Internet
Redwood City, CA 216,518 followers
Power secure collaboration on one intelligent platform
About us
Box (NYSE:BOX) is the Intelligent Content Cloud, a single platform that enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia. Visit box.com to learn more. And visit box.org to learn more about how Box empowers nonprofits to fulfill their missions.
- Website
-
http://www.box.com
External link for Box
- Industry
- Technology, Information and Internet
- Company size
- 1,001-5,000 employees
- Headquarters
- Redwood City, CA
- Type
- Public Company
- Specialties
- Cloud Content Management, File Sharing, Collaboration, FTP Replacement, Mobile Enterprise Security, Enterprise Content Management, Content Management, Enterprise Software, EFSS, Business software, Content Cloud , E-Signature, and E-Sign
Products
Box
Cloud Content Collaboration Software
Your business runs on content, and it’s time you put it to work. Sales contracts, product specs, marketing assets and videos — files like these are at the heart of your work, no matter your industry. Box is a single, secure, easy-to-use platform built for the entire content lifecycle, from file creation and sharing, to co-editing, e-signature, classification, and retention. There’s a reason 67% of the Fortune 500 trust Box. The Content Cloud is where real work gets done.
Locations
-
Primary
Get directions
900 Jefferson Ave
Redwood City, CA 94063, US
Employees at Box
Updates
-
Most enterprises now have access to more AI agents than they know what to do with. Stop thinking about the single agent you are going to use. Start thinking about the agentic ecosystem and how multiple agents cooperate together to do work for you. Our CTO Ben Kus says the distinction matters. Frontier agents like Claude, ChatGPT, and Gemini are generalists. They can use MCP servers, write code, and handle a wide range of knowledge work. Platform agents like Box AI are specialists. They are built to find, analyze, and act on the unstructured data inside a specific platform in ways a generalist agent cannot replicate. You do not have to choose. A frontier agent can reach into Box headlessly to retrieve content. Or it can go further and ask Box AI to do the specialized work, create a document, generate a report, analyze a folder, and hand the result back. The generalist orchestrates. The specialist executes. That is what a mature agentic architecture looks like. Not one agent doing everything. Multiple agents cooperating, each doing what it does best.
-
AI agents read files. That is the whole point. But when an agent can read any file the user has access to, sensitive content that was never meant to reach an AI pipeline suddenly can. Classification-based access policies in Box solve this at the content layer. Admins can now define exactly which agents are allowed to read which content based on how that content is classified in Box Shield. A file classified as Confidential or higher can be restricted from agent access entirely, even if the user running the agent has permission to open it manually. This demo shows what that looks like in practice. Read access control for AI agents, configured directly in Box, enforced automatically across Box AI, Claude, ChatGPT, Gemini, and any agent connecting into Box. The classification you already have in Box Shield now extends to every agent that tries to read your content.
-
Enterprise AI only delivers real value when it works with content in a transparent, secure, and trustworthy way. That's why Box is proud to join NVIDIA and other industry leaders in the Open Secure AI Alliance. Together, we're advancing open-source tools and best practices for secure AI, including agent guardrails, prompt injection defenses, secure tool use, and auditable AI workflows. At Box, we're helping organizations unlock the value of their enterprise content with AI while maintaining the security, governance, compliance, and transparency they depend on. Through this collaboration, we're contributing to an open ecosystem that helps people build and deploy AI they can trust.
-
-
The content + AI event of the year just added another visionary voice. Intel CEO Lip-Bu Tan is taking the BoxWorks main stage alongside Box CEO Aaron Levie for a live conversation on where AI and the enterprise are headed next. Across our agenda, discover how to make your business content work securely with any AI agent, assistant, or workflow, while preserving the permissions, governance, and compliance controls you already trust. Not only will you get to hear from the brightest minds in AI innovation, but you’ll learn how to: • Protect sensitive content and secure the agents that access it • Turn enterprise knowledge into trusted AI insights • Automate business-critical workflows across your tech stack • Build practical skills through technical sessions, Master Classes, and hands-on demos See what’s possible when your content becomes the secure foundation for enterprise AI. Explore the agenda and speaker lineup and let us know what you’re most excited for.👇 See you on November 5–6 in San Francisco! Leave a comment today to receive information on discounted registration.
-
-
Most teams solving the "agents need both structured data and unstructured context" problem are doing it by copying documents into a second system. That creates a maintenance problem, a permissions problem, and a governance problem all at once. The Box MCP server for Databricks takes a different approach. Instead of pre-copying your Box content into the lakehouse, your Databricks agents retrieve what they need at the point of work. The original file stays in Box. The permissions stay in Box. The version history, metadata, and retention policies stay in Box. Only the information the current task needs crosses the boundary between platforms. The authorization model is worth understanding. Every request clears two independent checkpoints: Databricks controls who can invoke the Unity Catalog connection, and Box independently evaluates whether that identity can access the underlying content. A request that Databricks approves can still be denied by Box if the identity does not have access to the file. The effective access is the intersection of both. Three outcomes this produces for enterprise teams: → Inherited Box permissions. Databricks users and agents can reach only the content available to the identity running the operation. → No complex data duplication. You do not need to maintain a full copy of your Box repository inside Databricks. → Governed AI access. Every content request is subject to Box authorization, end to end. Your content stays a single source of truth in Box. Your Databricks agents get the context they need to do useful work. The Box MCP server is available now on Databricks Marketplace.
-
-
Our CTO Ben Kus put two ChatGPT models head to head on the same procurement question: which suppliers should we drop and what are they really costing us? GPT 5.2 produced a sophisticated analysis, the kind that would take a person hours to complete manually. It was genuinely useful. GPT 5.6 Sol did the same analysis. The results were better across the board, more nuanced, more thorough, and more aligned to the complexity of the question. Ben describes it as the difference between a newer analyst and a more experienced one. Not every task needs the most powerful AI model available. But when the analysis is complex, the decision is strategic, and mistakes are costly, that's exactly when model quality matters most. So the question is not whether you need the newest model. It is knowing which workflows do.
-
We put Anthropic’s Claude Opus 5 through Box's Complex Work Eval — our agentic benchmark for real enterprise document work: retrieve the source files, reason across spreadsheets, PDFs, and decks, and produce the actual deliverable a knowledge worker would. It's a clear step up from the prior generation. Opus 5 scores 68% overall to Opus 4.8's 63%, winning a clear majority of tasks — and the gap is widest exactly where the work is hardest: the exhaustive, multi-step analysis that drives real decisions. A few things it did especially well: → Due diligence (76% vs 65%): it stayed accurate as the number of required findings grew, rather than catching the obvious items and stopping. → Life Sciences (63% vs 49%): intersecting several datasets under a strict matching rule to find the items common to all, where the prior model over-included partial matches. → Legal (79% vs 71%): a clause-by-clause contract review where it scored every item completely and correctly cleared the clauses acceptable under an exception. Across the board, Opus 5 is more reliable on the analytical work enterprises depend on — the kind where completeness and precision are the whole job.
-
-
Evelyn Ngai inherited Samsung Semiconductor's GRC operation and a vendor review process that ran entirely on email: inbound requests, risk scoring, evidence collection, manual review of every document. "Originally, it took three to five days to look at each vendor and decide whether or not to use them. Per vendor, it's only like half a day." What changed is two distinct Box AI agents. The first extracts metadata from vendor documentation and scores each vendor against Samsung's own risk criteria, no matter what format the documents arrive in. It hands off autonomously to a second, specialized security agent, which independently reviews the same documentation and flags exceptions against Samsung's security rubric. The team then works through the exceptions that the second agent surfaces. GRC teams have always wanted to run exception-based review. The obstacle was that deciding what counted as an exception required reading the document first.
-
The leaders shaping the future of enterprise AI are coming together, and we could not be more excited. What does it take to move AI from possibility to practice? Find out at BoxWorks 2026, November 5-6 in San Francisco. Join IT and business leaders for visionary keynotes, breakout sessions, hands-on demos, and real-world conversations about how organizations are putting AI to work. Hear from innovators across the ecosystem, including NVIDIA CEO Jensen Huang, leaders from Intel and Box, and discover how Box's partner ecosystem, including OpenAI, Google Cloud, AWS, Microsoft, Anthropic, and IBM, is helping shape the future of enterprise AI. Plus, a dedicated day of hands-on workshops on November 6 to build practical AI skills across Box AI, intelligent content, automation, governance, and enterprise best practices, with actionable guidance you can apply immediately. This is the event of the year. We cannot wait to see you there. What are you looking forward to most? Tell us in the comments. 👇