---
title: "Documents — React Box documentation"
description: "Anatomy of a vault document: files, comments, visibility, activity log, and associated permissions."
url: https://www.react-box.com/en/docs/vault/documents
lang: en
---

The vaultDocuments

# Documents

A document is the unit of exchange in the vault. It bundles a name, a folder, one or more files, tags, comments, and a complete activity log.

Updated on September 11, 2026

## Anatomy of a document

Seven elements structure every document. All of them are visible in the side panel when you open a document.

* Name  
The title you see in the list. Editable at any time by anyone holding the document:manage permission.
* Folder  
The folder where the document lives. You can move it from one folder to another.
* Files  
One or more attached files. You can add, remove, or replace them at any time.
* Tags  
Your custom labels. Optional, but useful to find a document months later.
* Comments  
A discussion thread attached to the document, shared between the business and its agency.
* Visibility  
Who sees this document: your accounting firm, or only certain roles inside your organization. Two settings, detailed below.
* Archived  
A document may belong to an archive — a closed financial year, set aside. It keeps its folder but only shows to authorised people, and stops being editable.

## Files

Attached files are stored in a private Cloudflare R2 bucket, accessible only via short-lived signed URLs.

Constraints

* Maximum size per file: 20 MB.
* Accepted formats: PDF, images (JPEG, PNG, WebP), Office documents (Word, Excel, PowerPoint), plain text, and CSV. Any other format is rejected — HEIC photos taken on an iPhone are converted by the mobile app before upload.
* The file's actual content is verified at upload to make sure it matches the declared type. A PDF renamed as .jpg will be rejected.

How upload works

The file is uploaded directly from your browser to Cloudflare R2 via a pre-signed URL. React Box never relays your file through its servers. Once the upload completes, the application only records the reference (R2 key, original name, size, type).

When the agency uploads a file

A member of the accounting firm can also attach files to a document (processing evidence, accounting entries, letters). These files are flagged as coming from the agency and show up as such in the activity log.

## Comments

Every document has its own discussion thread. Comments are visible to everyone who has access to the document — your internal collaborators as well as members of the accounting firm linked to your client file.

## Activity log

Every action taken on a document is recorded. The log serves as a complete audit trail: who did what, when, on which document.

* `DOCUMENT_CREATED`  
Document created.
* `DOCUMENT_UPDATED`  
Document changed — renamed, or visibility rules updated.
* `DOCUMENT_MOVED`  
Moved to another folder.
* `DOCUMENT_ARCHIVED`  
Document archived, with the archive it was filed into.
* `DOCUMENT_UNARCHIVED`  
Taken out of its archive: the document is editable again.
* `FILE_UPLOADED`  
File uploaded.
* `FILE_DELETED`  
File removed.
* `FILE_VIEWED`  
File opened in the viewer. Repeat views by the same person are grouped over half an hour.
* `FILE_DOWNLOADED`  
File downloaded. Repeat downloads of the same file by the same person are grouped over twelve hours.
* `FILE_OPTIMIZED`  
Automatic file-size optimisation, with the size before and after.
* `TAG_ADDED`  
Tag added.
* `TAG_REMOVED`  
Tag removed.
* `DOCUMENT_DELETED`  
Moved to the trash.
* `DOCUMENT_RESTORED`  
Restored from the trash.
* `DOCUMENT_PURGED`  
Permanently deleted.
* `SHARE_LINK_CREATED`  
Public share link created.
* `SHARE_LINK_REVOKED`  
Public share link revoked.

## Controlling what the agency sees

By default, every document is visible to your linked accounting firm. Two levers let you restrict that visibility case by case.

* Hide from agency  
Ticking this box makes the document entirely invisible to members of the accounting firm. Useful for sensitive items that don't need processing (NDAs, confidential HR records).
* Limit to given roles  
You can restrict access to specific internal roles only. Other users in your organization won't see the document.

These settings are visible in the activity log: a "Document changed" entry appears on every change.

## When the document goes to an archive

Once a financial year is closed, its paperwork is archived in batches. An archived document does not change folder and stays linked to its invoice, but it leaves listings, counts and searches: it is only read from the Archives screen, and only by people holding the archiving permission. It can no longer be renamed, moved or commented on until it comes back out.

### [Archives](https://www.react-box.com/en/docs/vault/archives)

Why and how to archive a financial year, what an archived document no longer allows, and how to go back.

Read the page

## Sharing a document by link

For a recipient with no React Box account — a bank, a notary, an auditor — a secure public link replaces the email attachment.

* Expiry — one day, seven days, thirty days, a date of your choosing, or no limit. A dated link expires on its own, which an email never does.
* Password — optional, to be shared through a channel other than the link itself.
* View only — the recipient reads the document in their browser without being able to save the file.
* Notify on access — you learn when the link was first opened.

Every link you create stays listed on the document, with its status, its expiry date and the number of views and downloads. You can copy it, email it to several recipients from React Box, or revoke it: revoking cuts access immediately, even for someone who already holds the link.

The public page asks for an anti-bot check before opening the document, and exposes nothing else — neither the vault nor any other record.

## Associated permissions

Two permissions govern document usage.

* document:view — read a document and its files.
* document:manage — create, edit, move, delete a document. Includes document:view.
