Agency access
An accounting firm never has its own vault: it accesses each of its clients' vaults through an explicit access link. This page details how access is configured, what a member of the agency can see, and how you keep control.
Updated on September 11, 2026
The basic rule
Business-type organizations own a vault. Agency-type organizations don't. When an agency is linked to your business, its members access your vault exactly like your own collaborators — with their own permissions, their own activity feed, their own logged sign-ins.
A two-step link
The agency's access relies on two distinct decisions: your business links the agency, then the agency designates which of its members handle your file.
1. The org-to-org link
You, the business, invite your agency into React Box. The link sets the perimeter: your agency gets access to your vault, your chat, your categorization. You can revoke this link at any time from your settings.
2. The individual assignment
On the agency side, the administrator assigns its collaborators to the client files they take on. An accountant only has access to the businesses for which they were explicitly assigned.
Two roles on the agency side
Within an agency, two roles structure access to client files.
Supervisor
Full visibility over the client file: every folder, every document, and the ability to drive the purchase-invoice review. Agency administrators automatically get this role across all of their clients.
Member
Operational access to the file without supervisory power. Ideal for accountants who handle documents day to day.
What the agency sees
By default, a member of the agency assigned to your file sees your entire vault, except for items you have explicitly hidden.
- Every document in the vault, as soon as it is uploaded.
- The attached files, via short-lived signed URLs.
- Your tags and tag categories, which they can use to annotate your documents.
- The full activity log of the document, including actions by your collaborators.
- The file's archives: the firm archives a financial year on your vault and reads archived paperwork without you opening a single setting. It comes with the link, it is not a permission to tick.
Hide a document
Client side
When the agency files documents
Agency side
Access guarantees
Three complementary mechanisms protect access end to end.
- Every agency API request is scoped to the matching client file: an accountant can't accidentally access another client's file.
- Every agency action is logged in the document's audit trail.
- You can break the link with your agency at any time. Access is cut instantly.