Documents
A document is the unit of exchange in the vault. It bundles a name, a folder, one or more files, tags, comments, and a complete activity log.
Updated on September 11, 2026
Anatomy of a document
Seven elements structure every document. All of them are visible in the side panel when you open a document.
Name
The title you see in the list. Editable at any time by anyone holding the document:manage permission.
Folder
The folder where the document lives. You can move it from one folder to another.
Files
One or more attached files. You can add, remove, or replace them at any time.
Tags
Your custom labels. Optional, but useful to find a document months later.
Comments
A discussion thread attached to the document, shared between the business and its agency.
Visibility
Who sees this document: your accounting firm, or only certain roles inside your organization. Two settings, detailed below.
Archived
A document may belong to an archive — a closed financial year, set aside. It keeps its folder but only shows to authorised people, and stops being editable.
Files
Attached files are stored in a private Cloudflare R2 bucket, accessible only via short-lived signed URLs.
Constraints
- Maximum size per file: 20 MB.
- Accepted formats: PDF, images (JPEG, PNG, WebP), Office documents (Word, Excel, PowerPoint), plain text, and CSV. Any other format is rejected — HEIC photos taken on an iPhone are converted by the mobile app before upload.
- The file's actual content is verified at upload to make sure it matches the declared type. A PDF renamed as .jpg will be rejected.
How upload works
The file is uploaded directly from your browser to Cloudflare R2 via a pre-signed URL. React Box never relays your file through its servers. Once the upload completes, the application only records the reference (R2 key, original name, size, type).
When the agency uploads a file
A member of the accounting firm can also attach files to a document (processing evidence, accounting entries, letters). These files are flagged as coming from the agency and show up as such in the activity log.
Comments
Every document has its own discussion thread. Comments are visible to everyone who has access to the document — your internal collaborators as well as members of the accounting firm linked to your client file.
Activity log
Every action taken on a document is recorded. The log serves as a complete audit trail: who did what, when, on which document.
DOCUMENT_CREATEDDocument created.
DOCUMENT_UPDATEDDocument changed — renamed, or visibility rules updated.
DOCUMENT_MOVEDMoved to another folder.
DOCUMENT_ARCHIVEDDocument archived, with the archive it was filed into.
DOCUMENT_UNARCHIVEDTaken out of its archive: the document is editable again.
FILE_UPLOADEDFile uploaded.
FILE_DELETEDFile removed.
FILE_VIEWEDFile opened in the viewer. Repeat views by the same person are grouped over half an hour.
FILE_DOWNLOADEDFile downloaded. Repeat downloads of the same file by the same person are grouped over twelve hours.
FILE_OPTIMIZEDAutomatic file-size optimisation, with the size before and after.
TAG_ADDEDTag added.
TAG_REMOVEDTag removed.
DOCUMENT_DELETEDMoved to the trash.
DOCUMENT_RESTOREDRestored from the trash.
DOCUMENT_PURGEDPermanently deleted.
SHARE_LINK_CREATEDPublic share link created.
SHARE_LINK_REVOKEDPublic share link revoked.
Controlling what the agency sees
By default, every document is visible to your linked accounting firm. Two levers let you restrict that visibility case by case.
Hide from agency
Ticking this box makes the document entirely invisible to members of the accounting firm. Useful for sensitive items that don't need processing (NDAs, confidential HR records).
Limit to given roles
You can restrict access to specific internal roles only. Other users in your organization won't see the document.
When the document goes to an archive
Once a financial year is closed, its paperwork is archived in batches. An archived document does not change folder and stays linked to its invoice, but it leaves listings, counts and searches: it is only read from the Archives screen, and only by people holding the archiving permission. It can no longer be renamed, moved or commented on until it comes back out.
Archives
Why and how to archive a financial year, what an archived document no longer allows, and how to go back.
Read the pageAssociated permissions
Two permissions govern document usage.
- document:view — read a document and its files.
- document:manage — create, edit, move, delete a document. Includes document:view.