Skip to content

The vault

Agency access

An accounting firm never has its own vault: it accesses each of its clients' vaults through an explicit access link. This page details how access is configured, what a member of the agency can see, and how you keep control.

Updated on August 14, 2026

The basic rule

Business-type organizations own a vault. Agency-type organizations don't. When an agency is linked to your business, its members access your vault exactly like your own collaborators — with their own permissions, their own activity feed, their own logged sign-ins.

A two-step link

The agency's access relies on two distinct decisions: your business links the agency, then the agency designates which of its members handle your file.

  1. 1. The org-to-org link

    You, the business, invite your agency into React Box. The link sets the perimeter: your agency gets access to your vault, your chat, your categorization. You can revoke this link at any time from your settings.

  2. 2. The individual assignment

    On the agency side, the administrator assigns its collaborators to the client files they take on. An accountant only has access to the businesses for which they were explicitly assigned.

Two roles on the agency side

Within an agency, two roles structure access to client files.

  • Supervisor

    Full visibility over the client file: every folder, every status, the ability to validate and close out. Agency administrators automatically get this role across all of their clients.

  • Member

    Operational access to the file without supervisory power. Ideal for accountants who handle documents day to day.

What the agency sees

By default, a member of the agency assigned to your file sees your entire vault, except for items you have explicitly hidden.

  • Every document, whether in draft on your side or not.
  • The attached files, via short-lived signed URLs.
  • Your tags and tag categories, which they can use to annotate your documents.
  • The full activity log of the document, including actions by your collaborators.
The agency never sees documents you marked "Hide from agency", nor documents limited to specific internal roles.

Hide a document

Client side

For every document, you can enable the "Hide from agency" option. The document becomes entirely invisible to members of the linked agency — including in lists, counters, and searches. Useful for confidential HR documents, sensitive contracts, or anything you want to keep in the vault without sharing it.

When the agency files documents

Agency side

Agency members can also drop documents and files into your vault — for example, a tax declaration they prepared, an official letter, or a certificate. These uploads are flagged as coming from the agency in the activity log, so you immediately see who did what.

Access guarantees

Three complementary mechanisms protect access end to end.

  • Every agency API request is scoped to the matching client file: an accountant can't accidentally access another client's file.
  • Every agency action is logged in the document's audit trail.
  • You can break the link with your agency at any time. Access is cut instantly.