Enforce Content Owner's Box AI Home Policy for External Collaborators (Prevent External Search on Owned Content)
Background & Current Behavior:
Our organization has enabled Box AI but intentionally disabled Box AI Home. However, we discovered that external collaborators who have Box AI Home enabled in their own tenant can still use Box AI Home to search for and access our content. This applies to our content they have explicit permissions for, as well as content they do not have permissions for but have a viewing history of and can preview via a shared link.
Problem & Security Risk:
From a security, data privacy, and compliance perspective, if an organization restricts the use of Box AI Home, this policy must be strictly enforced on all owned content, regardless of the external collaborator's tenant settings. The current behavior creates a critical loophole where our confidential data is processed and exposed through an AI interface that we have deliberately disabled as an organization.
We acknowledge that the risk of confidential data exposure via Box AI Home theoretically would not exist assuming access control and permission management are absolutely perfect. However, in reality, permission management can sometimes be imperfect or delayed. We are requesting this restriction as an essential fail-safe (defense-in-depth) to prevent unintended data exposure in such realistic scenarios.
Feature Request:
We strongly request a feature—either at the tenant level or the folder level—that prevents external users from discovering or searching our owned content via Box AI Home. The content owner's AI policy must always take precedence over the collaborator's tenant settings to ensure complete data governance and serve as a crucial safety net for our organization.
背景と現在の挙動:
当組織では、Box AIを有効にする一方で、Box AI Homeは意図的に無効化しています。しかし、自身のテナントでBox AI Homeを有効にしている外部コラボレーターは、Box AI Homeを使用して当社のコンテンツを検索し、アクセスできてしまうことが判明しました。これには、彼らが明示的な権限を持つ当社のコンテンツだけでなく、権限がなくとも過去に閲覧履歴があり、共有リンクでプレビュー可能なコンテンツも含まれます。
課題とセキュリティリスク:
セキュリティ、データプライバシー、コンプライアンスの観点から、組織がBox AI Homeの利用を制限している場合、そのポリシーは外部コラボレーター側のテナント設定に関わらず、自社が所有するすべてのコンテンツに対して強制的に適用されるべきです。現在の挙動は、当社が組織として意図的に無効化しているAIインターフェース経由で、当社の機密データが処理・露出されてしまうという重大な抜け穴を生み出しています。
AI Homeによる機密データの露出は、もともとの権限管理が完璧に行われている前提であれば理論上存在しないリスクであることは理解しています。しかしながら、現実の運用において権限管理が完全に漏れなく行われないケースは起こり得ます。私たちは、そうした現実的なシナリオにおける予期せぬデータ露出を防ぐための、不可欠なフェイルセーフ(多層防御の予防線)としてこの制限を要望しています。
機能リクエスト:
自社が所有するコンテンツに対して、外部ユーザーがBox AI Home経由で検索や発見をすることを防ぐ機能(テナントレベルまたはフォルダレベルの設定)を強く要望します。完全なデータガバナンスを確保し、組織の重要なセーフティネットとして機能させるために、コンテンツ所有者のAIポリシーがコラボレーターのテナント設定よりも常に優先される必要があります。