Skip to main content

CDP Took Confidential Files Off Teams and Email With Files.com

Matching the convenience of familiar tools let one IT specialist enforce departmental access across more than 200 accounts.
Contributor Development Partnership (CDP)Files.com

Contributor Development Partnership (CDP) runs collaborative fundraising for more than 230 public radio and television stations across the United States. Founded inside WGBH in 2011 and independent since 2018, the public benefit corporation ingests station donor and viewing data, processes it through an analytics platform, and returns the reports, contact lists, and results that drive station fundraising.

That business rests on being careful with other organizations’ data. CDP’s own workforce, meanwhile, is distributed across the country. Sensitive internal legal documents and finance tax records also had to cross the internet, often through whichever tool was closest to hand. CDP used Files.com to take those confidential exchanges off Teams and email without making them harder, giving one administrator a governed channel across more than 200 accounts.

Confidential Files Took Whatever Path Was Open

For years, the closest tools were Microsoft Teams, email, and SharePoint. A legal document went out as an attachment. A batch of files moved through a chat thread. Training videos were distributed as SharePoint links that recipients clicked to play. Nobody chose any of this as policy. Each channel was simply there, and for a workforce scattered across the country, the attachment button is always the shortest path.

The cost of that habit is what happens after the send. A file dropped in a chat or attached to an email is out of IT’s hands the moment it leaves. It cannot be recalled, its audience is whoever the thread reaches, and nobody can later say who opened it. Confidential material moved this way routinely, at a company whose whole business depends on trust in its data handling.

The most sensitive material sat in the worst position. Legal documents carrying personal information and finance tax records lived in shared storage that had grown from a single root, where a permission change at the top rippled across every folder and nothing kept technology or marketing staff out of files they had no reason to see.

The condition persisted because no policy could outrun convenience. A memo does not stop a remote employee from dropping a file into the chat window already open in front of them. Ending the habit required an alternative that was just as easy to use, and that one administrator could actually enforce.

One Governed Estate, Fenced by Department

The replacement had three requirements. It had to be as easy as the habit it displaced: send a link, click it, the file opens. It had to fence departments from one another, so that a document’s audience is set by where it lives, not by who happens to hold a link. And it had to stay enforceable by a single administrator across more than 200 user accounts.

CDP made Files.com that channel: the company’s internal file server, and the mandated path for every confidential transfer.

Leo Marino, CDP’s IT specialist, remediated permissions in place, moving sensitive files into subdirectories and applying permission fencing to private, legal, and finance folders. Files.com permission fences stop inherited access at each folder boundary. Technology and marketing staff cannot reach a legal document containing personal information or a finance tax record; those folders are simply not there for them. Microsoft Entra single sign-on and SCIM provisioning create users and apply group memberships automatically, while group-level folder permissions decide what each role can reach. Using Files.com’s user impersonation feature, Marino sees the site exactly as any given user does, so each fence is verified rather than assumed.

Training and marketing videos moved off SharePoint and onto Files.com share links with preview-only permissions, backed by public hosting. The recipient clicks a link and the video plays in the browser, which is exactly what the old SharePoint links did. The habit stayed the same. What changed is that the link now lives on the governed platform, and no downloadable copy rides along with it.

Confidential Exchange Now Runs Where IT Can See It

With Files.com as the mandated channel, CDP replaced ad-hoc sharing over chat and email with a governed path that staff actually use.

  • Confidential files no longer travel through Teams chats or email attachments. They move through fenced, logged folder access instead.
  • Departmental data is invisible outside the department that owns it. Personal information in legal documents and tax records in finance folders are unreachable for technology and marketing staff, by construction rather than by trust.
  • Every kind of internal sharing has one answer. Videos play from a preview-only link, documents move through fenced folders, and all of it lands in the same audit trail.
  • A single IT specialist enforces the whole estate, with the directory handling provisioning and groups carrying the permissions.
Someone was trying to do it through Teams, and I said no.
Leo Marino, IT Specialist, CDP

The no holds because the yes costs nothing: the governed path is as fast as the habit it replaced.

The Easy Way and the Secure Way Are Now the Same

Today, a CDP employee anywhere in the country who needs to move a sensitive document does not make that decision alone in whatever tool happens to be open. The path already exists, it is as quick as an attachment, and it carries the fences and the record the company is accountable for. A legal file that once rode a chat thread to whoever was in it now reaches exactly the people its folder permits, and IT can say who touched it.

CDP did not get there by policy. A memo was never going to beat the attachment button. What moved the behavior was making Files.com just as easy to reach, so that one administrator could say no to Teams because yes was already one click away.