Skip to main content

A Components Manufacturer Kept OneDrive—and Replaced Citrix ShareFile With Files.com for Sensitive Sharing

The shift gave InfoSec one approved, auditable path for files crossing the company boundary without disrupting day-to-day work.

A global components manufacturer supplies engineered parts to OEMs in the transportation and building products industries. It runs a multi-site footprint with extensive dealings with OEMs, vendors, and other outside parties.

A business shaped like that hands files to outside parties constantly. Contracts and legal documents go to vendors and outside counsel, engineering material goes to OEM customers, and working documents move between partners on two continents. Internally, day-to-day documents live in OneDrive. The question started where those two facts met: which channel a sensitive file takes when it is handed to an outsider.

The company’s answer was to draw a boundary rather than replace its collaboration suite: it kept OneDrive for internal collaboration, retired Citrix ShareFile, and made Files.com the governed channel for sensitive external sharing.

InfoSec Wanted One Channel for Sensitive External Sharing

The files the company most needs to control are the ones that leave the company. Sensitive material bound for third parties, legal documents above all, needs controls that everyday work does not. The company’s InfoSec team looked at that class of file and set a requirement: one approved, auditable channel for it, separate from the general-purpose store that holds everyone’s everyday work. At the same time, a separate population of users did its external sharing through Citrix ShareFile, so external sharing ran on two tools with two different governance postures. InfoSec wanted one approved way to hand a sensitive file to a customer, a vendor, or a lawyer. The specification was plain: sensitive external sharing needed one governed front door.

The Collaboration Suite Could Not Go, and ShareFile Habits Had to Move

The obvious fix was unavailable. OneDrive is the legitimate internal document store across the company’s workforce, and it does that job well. Shutting it down to control one class of traffic was never on the table. Whatever the company did had to carve external sharing of sensitive files out of OneDrive specifically, while everyday internal collaboration went on untouched.

ShareFile set the second constraint. Its users had years of habits built into the tool: address books of repeat recipients, and live collaboration with outside parties on shared documents. A replacement that could not absorb those workflows would not retire ShareFile. It would just add a third tool.

So the requirement was a dedicated external-sharing channel that InfoSec could stand behind: links with expiration, passwords, and recipient control, the company’s own sign-in in front of it, a record of every share, and enough ease of use that people would take the approved path instead of routing around it. The InfoSec team settled the question by policy: sensitive files leave the company through Files.com, and OneDrive stays the internal store.

A Governed Link on the Company’s Own Domain, With a Reason Attached to Every One

Files.com became the front door for handing files to outside parties, sitting alongside OneDrive rather than replacing it. When a sensitive file needs to leave the company, it moves onto Files.com and goes out as a Share Link on the company’s own domain, carrying the controls the platform enforces: expiration, passwords, and recipient restrictions, with every access landing in the audit record.

The company added a discipline of its own on top. Every Share Link a user creates must carry an internal note recording what the link is for—a requirement Files.com built into the platform after the company asked for it. A review of outstanding links therefore reads as a list of reasons rather than a list of mysteries: who shared what, with whom, and why.

Access follows the same identity model as the rest of the company’s estate. Internal users sign in through Okta with two-factor authentication, and folder access is granted through groups, so what a person can reach and share is decided by the team they belong to.

Moving ShareFile’s Users Without Losing Their Workflows

The consolidation came in 2024. Rather than run two sharing tools side by side indefinitely, the company decommissioned Citrix ShareFile and moved its users onto Files.com. The Files.com onboarding team ran a working session with the transferring users to map ShareFile-era workflows onto the platform, and the two workflows those users most depended on both landed. Managed recipient lists took the place of ShareFile address books, so a repeat distribution goes to the same set of contacts without rebuilding the list each time. And live collaboration survived the move: an outside party can open and edit a shared spreadsheet through the Share Link itself, with no Files.com account, a capability Files.com shipped after the migration surfaced the need.

One Approved Way to Hand a Sensitive File to an Outside Party

With ShareFile retired and the policy in force, the company replaced two external-sharing tools with different governance postures with a single channel it can fully account for. The change shows up as risk removed and overhead removed:

  • Sensitive files leave through the one channel InfoSec approved. Every external share of that class runs through Files.com, behind Okta sign-in, on a link that expires and can be revoked.
  • Citrix ShareFile is gone from the estate: one platform to govern, one policy to enforce, and one audit trail to consult instead of two.
  • Every outstanding Share Link carries a documented purpose, so reviewing external access is a lookup rather than an investigation.
  • OneDrive kept its job. Day-to-day documents across the company’s workforce never moved, because the fix carved out one class of traffic instead of forcing a new home for everything.

Use has kept spreading since. As more teams route their external sharing through the platform, they can adopt an established pattern—a folder, a group, and a link—rather than design another sharing process. InfoSec has already approved it.

Governing the Traffic Instead of Replacing the Toolset

Drawing that line, and putting one approved platform on the outside of it, is what makes external sharing at the company a policy it can account for.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes