Skip to main content
AccessOwl integrates with Box to provision and deprovision user access in your Box organization.

Capabilities

Provisioning

AccessOwl creates user accounts with the specified roles/permissions during access requests.

Deprovisioning

AccessOwl removes users from your Box organization during access revocations.

Prerequisites

  • Admin access to your Box Admin Console, so you can add the integration account and change its role.

Setup

1

Add Box in AccessOwl

Either add a new application or open Applications and click the +-symbol, then continue.
2

Add the integration account as a managed user

AccessOwl shows you the integration account’s email address. In Box:
  • Open the Admin Console and go to Users & Groups.
  • On the Managed Users tab, click Add Users, then Add Users Manually.
  • Enter a name and the integration account’s email address.
  • Click Save.
3

Give the integration account the Admin role

Box allows a single Admin per organization, so this step transfers the Admin role from the current Admin to the integration account. Logged in as the current Box Admin:
  • In Admin Console > Users & Groups, open the Managed Users tab and click your own Admin account.
  • In the Role and Access Permissions section, click Edit, then Change Account Admin.
  • Pick the role you keep for yourself, type the integration account’s email address into the New Admin field and select it from the search results.
  • Click Save Changes and confirm the transfer from the verification email Box sends you.
Both email domains involved need to be verified in Box’s Domain Management. See Box’s guide on transferring Admin privileges.

FAQ

Check the integration account’s role in Admin Console > Users & Groups. If it is Co-admin or Member, change it to Admin and click Retry on the Box application in AccessOwl. The connection completes on its own once the role is in place.
If Box access is already handed out through a group in your identity provider, you can connect it as an identity-provider-managed application instead and skip the integration account entirely.
Last modified on September 3, 2026