SOURCE-CHECKED GUIDE · BUSINESS DOCUMENTS
Dropbox, OneDrive, or Box file requests for client intake
Select an upload-only client intake path with the right plan and metadata controls.
All three services can collect files from people without their own service accounts, subject to the configured settings. Choose a pilot from the work that follows upload: Dropbox for an existing Dropbox intake folder, OneDrive for Business when the processing team already works there and an administrator has enabled file requests, or Box Business or higher when structured submission fields matter. Box metadata fields require that metadata be enabled for the enterprise. Dropbox Microsoft Box
| Decision point | Dropbox | OneDrive for Business | Box |
|---|---|---|---|
| Sender access | People without Dropbox accounts can upload (Dropbox). | People without OneDrive accounts can upload without seeing folder contents (Microsoft). | People normally need no Box account to upload; an administrator can require login (Box). |
| Intake fields | Test how you will collect the client reference your team needs. | Test how you will collect and validate client identifiers. | Business or higher can use required metadata fields if metadata is enabled for the enterprise (Box). |
| Capacity | Uploads use the request owner’s storage; file size and deadline limits depend on the plan (Dropbox). | Confirm upload and storage limits in your tenant. | Confirm upload and storage limits on the proposed plan. |
| Approval gate | The destination is private by default; check who on your team needs access (Dropbox). | An administrator must enable file requests. Microsoft excludes OneDrive home and Office 365 operated by 21Vianet or in Germany, so confirm the actual tenant’s support (Microsoft). | Check whether your login policy suits external clients. Folder requests cannot upload folders (Box). |
A request link does not settle who submitted a document. With OneDrive for Business, a name typed by an unauthenticated sender is not validated (Microsoft). Two clients could enter the same name, leaving staff to assign a sensitive file to the wrong case. If identity matters, require a client reference and a separate verification step in your intake procedure. For Box, decide whether requiring a Box login fits your client population and identity policy; the administrator controls that requirement (Box).
Check the internal handoff before buying. Dropbox’s private-by-default destination needs an access path for the people who process requests (Dropbox). If staff transfer files into case records, test whether the naming and any required metadata remain usable afterward. The supplied sources do not establish retention periods or deletion behavior for these choices. Apply your organization’s retention rule in the trial, including what should happen when a request closes or its staff owner changes.
Run a controlled pilot with a normal document, a file near your expected size ceiling, and a submission with an ambiguous client name. Have an external participant submit each file, then ask staff to identify it and transfer it into the correct case. Record whether the sender could see other submissions, which staff could access the destination, what limits the proposed plan imposed, and whether the transferred record meets your retention rule. Choose the path that passes those checks with acceptable effort for your clients.
This guide explains a workflow using the linked primary sources. We did not independently run every step or verify the result for your files; check the current service screen and your own output.
Primary sources: