A Benefits Administrator Replaced Progress MOVEit’s Person-to-Person Transfer With Self-Service Client Exchange on Files.com
A global benefits administrator runs health, wealth and leave benefits for many of the world's largest employers. Its product is administration itself: an employer hands the company the running of its benefits programs, and from that moment the two organizations exchange data constantly. Much of that data is participant health and retirement information, which the company handles under a HIPAA Business Associate Agreement. Alongside the automated feeds between systems runs a human layer of exchange, with HR teams at client companies, outside partners, and the administrator's own staff sending and receiving files with people beyond the company's walls. Every new client brings a new population of external users who need a secure way in.
Every New Client Ran Through One Team
Before Files.com, that human exchange ran on Progress MOVEit, and everything around it ran through the company's central Managed File Transfer team, by hand. Onboarding a new client meant the MFT team creating each user, building the folder structure, and assigning permissions, one request at a time. The controls were hand-built too: the blacklist that kept files from being shared out to free personal email domains was a list the company compiled and maintained itself inside MOVEit.
The cost was structural. A team whose job was governing file transfer spent its time executing file transfers, and every new client made the queue longer. Onboarding could not scale without adding central headcount.
There was no pressure valve, either. The company's corporate proxy blocks every generic file-transfer URL as a matter of policy, including Files.com's own generic address, precisely to keep shadow IT out of a business built on PHI. That policy is the right one for a company in its position. It also meant the slow, central channel was the only channel.
A Model Designed From the Ground Up
The manual model had survived because it delivered the one thing the company could not compromise: confidence in the security, control and auditing around regulated data. As the client base grew, that confidence was being bought with a bottleneck. The company's Managed File Transfer lead set the goal at the outset of the project: design the whole model from the ground up, keeping the security, control and auditing intact while removing the MFT team from the middle of every transaction.
That goal translated into a specification. The replacement had to run on the company's own domains, so the proxy would treat it as first-party infrastructure rather than a blocked sharing site. It had to take identity from the existing directory instead of relying on manually created accounts. It had to let business users stand up per-client spaces themselves, inside boundaries set centrally. Its recipient controls had to be at least as strict as the blacklist the team was keeping by hand. It had to feed the company's SIEM, and it had to carry a HIPAA BAA.
The company selected Files.com to be that sanctioned exchange layer.
Governed Tenants, All Under the Company's Name
The company deployed Files.com tenants as child sites: a production site for general use, a second production site locked down for a team with stricter requirements, and a dev/sandbox site where changes are proven before they touch production. Each tenant runs on its own branded custom domain.
The branding is not cosmetic. Because each tenant presents as first-party infrastructure on the company's own domain, it passes the proxy policy that blocks every generic sharing URL. Employees and clients reach a sanctioned channel that carries the company's name, and the shadow-IT block stays intact for everything else.
The rollout was deliberately parallel. MOVEit kept the system-to-system automated transfers it was already running, and Files.com took over the external human exchange.
Identity followed the same design. With SSO through Ping Identity, a user is provisioned automatically the first time they sign in, with group membership deciding their permissions. Folders and permissions come into existence with the user, and business users create per-client subfolders with scoped sharing themselves. Nobody files a request with the MFT team to onboard a client.
Share Links Out, Inboxes In, Policy Underneath
Day to day, the exchange runs on Files.com Share Links and Inboxes: links send files out to client contacts, inboxes collect files coming in, and both expire on the schedules the company sets. Recipient email domain restrictions decide where a share can go at all. When the company's security review called for the same domain controls it had run in MOVEit, Files.com shipped recipient whitelist and blacklist controls in response, including a pre-built blacklist of thousands of known scam and free email domains. The list the team had been maintaining by hand became a platform control it extends with entries of its own.
The same holds for account hygiene. Files.com user lifecycle rules disable dormant external accounts automatically, sending warning emails to the user beforehand, which is what lets the company enforce its internal policy of notifying external users before access is removed. And every login, upload, download and permission change streams to Microsoft Sentinel through the Files.com SIEM integration, landing alongside the rest of the company's security telemetry.
Onboarding Without the Queue
With the Files.com model in production, the company replaced a central manual workflow with self-service that is governed from above rather than executed from the center.
- Onboarding a new client no longer runs through the MFT team by hand. Users are provisioned on first sign-in, permissions follow their groups, and per-client folders and scoped sharing are created by the business users who need them.
- Controls that were maintained by hand are now enforced by the platform. The recipient blacklist, share expiration, and dormant-account cleanup with advance warning to the user all run without anyone remembering to run them.
The Human Side First
The company never had to treat replacing its legacy MFT platform as all-or-nothing. It peeled the person-to-person work off MOVEit and rebuilt it on Files.com as governed self-service, leaving the system-to-system automation in place. A legacy platform does not have to be replaced whole. The administrator started with the side people touch, and that turned out to be the side where the bottleneck lived.
Related Customer Stories
A Domain Registry Runs Self-Service Zone File Distribution for Vetted Outsiders on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in its own identity systems.
Read The Story
A Database Software Company Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while the company keeps no standing credentials for external uploaders.
Read The Story
A Network Security Vendor Retires Box by Moving a Handful of Beta Users to Files.com
The workload was small, but absorbing it into the file-transfer environment already feeding Oracle ERP eliminated an entire external sharing surface.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes