Skip to main content

CDFA Replaced Microsoft Teams Sharing and Email Attachments With Passwordless, Expiring Files.com Links

CDFA needed external recipients to open files without accounts or passwords while central IT retained control over permissions, expiration, and access records.
California Department of Food and Agriculture (CDFA)Files.com

The California Department of Food and Agriculture regulates California’s agricultural economy through its work in animal health and food safety, plant pest prevention, weights and measures, inspection, and oversight of the state’s fair network. It works with 50 county agricultural offices, fairgrounds, vendors, and other agencies, and as a California state agency it must answer Public Records Act requests from anyone who files one.

That is the fact that made the problem inevitable. Most of the documents CDFA sends go to people the department does not control. They arrive on other agencies’ domains, on vendors’ corporate accounts, or on Gmail and Hotmail. Some have no IT support of their own. None of them can be trained, provisioned, or troubleshot by Sacramento.

CDFA needed a delivery path outsiders could open without an account or password, while central IT retained permissions, expiration controls, and access records—including for public-records releases.

A One-Time Password in the Recipient’s Junk Folder

CDFA’s delivery tools were built for the opposite assumption. Sending a document through Microsoft Teams meant the recipient had to authenticate with a one-time password, and those passwords routinely landed in junk mail. Non-technical recipients could not get to their files at all. Email attachments covered the simple cases but stopped at the 100 MB message limit.

Every failure came back to central IT. The document had been sent; the recipient could not open it; a ticket got filed; and someone in Sacramento spent time walking an outside party through an authentication flow the department could not simplify, on a computer the department had never seen. That is the structural trap in authenticated sharing: the mechanism breaks at the recipient, which is exactly the point the sender cannot fix.

Send the File, Open the File, That’s It

As the support burden grew, IT drew a line under what the solution had to do.

I’m sending the file, you open the file, that’s it.
Karthik Ganesan, Information Technology Supervisor II, California Department of Food and Agriculture

The requirements followed from the recipients. Nothing to install and no account to create on the receiving end. No password to fish out of a junk folder. No assumption about what software the recipient runs. And none of that at the cost of control: the department still needed expiration controls on releases, permissions on every folder, a record of who accessed what, and one place for central IT to set policy for every division that came aboard.

CDFA selected Files.com to be that external delivery layer.

One Tenant, Run by Central IT, Division by Division

CDFA runs Files.com as a single tenant administered by central IT, with divisions brought on one at a time. The executive office went live first. The legal team followed, with its case documents and CDFA user accounts fenced off so that each division sees only its own files and people on the shared site. Adding a division does not add a platform: IT creates credentials for CDFA staff and folders, and the site-wide policies already apply.

Delivery itself is a Files.com Share Link. Staff upload the documents and send the recipient a passwordless link. The recipient clicks and the file opens in the browser, whatever domain they are on and whatever software they have. Links can carry an expiration the sender sets, folder-level permissions decide who inside CDFA can share what, and access and download notifications tell the sender the file was actually retrieved, so “did they ever get it” is answered by the log rather than a follow-up email.

Roughly 95 percent of what moves through the site is this one pattern: read-only documents going out to other divisions, outside entities, vendors, and the public.

Public Records Released With an Expiration Date

The pattern does its most consequential work on Public Records Act requests. When a request arrives, staff upload the responsive documents and send the requester a share link with a set expiration. Windows of six months, nine months, and one year are in use, matched to the disclosure. The requester opens the records directly from the link.

That gives legal something email never could: a defined access period per disclosure. A released record used to be an attachment living in someone’s mailbox indefinitely. Now each release turns itself off on a date the department chose, and the link’s activity is on the record.

Now the File Opens on the First Try

With Files.com in production for the executive office and legal team, CDFA replaced a delivery path that failed at the recipient with one that ends at a click.

  • External recipients open shared documents directly. The support loop that Microsoft Teams one-time passwords created for non-technical recipients is gone, and central IT no longer spends its time fixing other people’s authentication.
  • Files over email’s 100 MB cap move through the same links as everything else, so size stopped being a reason to find another channel.
  • Every public-records release carries an enforced access window instead of becoming an open-ended attachment.
  • Additional divisions can onboard onto the tenant central IT already runs, isolated from every other division’s files and governed by policies that are set once.

Delivery That No Longer Depends on the Recipient

Files.com moved the point of control back inside Sacramento: the expiration, the permissions and the access record belong to central IT, and the recipient’s only job is to click.