The vault
Agency access
An accounting firm never has its own vault: it accesses each of its clients' vaults through an explicit access link. This page details how access is configured, what a member of the agency can see, and how you keep control.
Updated on August 14, 2026
The basic rule
Business-type organizations own a vault. Agency-type organizations don't. When an agency is linked to your business, its members access your vault exactly like your own collaborators — with their own permissions, their own activity feed, their own logged sign-ins.
A two-step link
The agency's access relies on two distinct decisions: your business links the agency, then the agency designates which of its members handle your file.
1. The org-to-org link
You, the business, invite your agency into React Box. The link sets the perimeter: your agency gets access to your vault, your chat, your categorization. You can revoke this link at any time from your settings.
2. The individual assignment
On the agency side, the administrator assigns its collaborators to the client files they take on. An accountant only has access to the businesses for which they were explicitly assigned.
Two roles on the agency side
Within an agency, two roles structure access to client files.
Supervisor
Full visibility over the client file: every folder, every status, the ability to validate and close out. Agency administrators automatically get this role across all of their clients.
Member
Operational access to the file without supervisory power. Ideal for accountants who handle documents day to day.
What the agency sees
By default, a member of the agency assigned to your file sees your entire vault, except for items you have explicitly hidden.
- Every document, whether in draft on your side or not.
- The attached files, via short-lived signed URLs.
- Your tags and tag categories, which they can use to annotate your documents.
- The full activity log of the document, including actions by your collaborators.
Hide a document
Client side
When the agency files documents
Agency side
Access guarantees
Three complementary mechanisms protect access end to end.
- Every agency API request is scoped to the matching client file: an accountant can't accidentally access another client's file.
- Every agency action is logged in the document's audit trail.
- You can break the link with your agency at any time. Access is cut instantly.