An EHS Software Vendor Kept SharePoint Locked Down by Moving External File Sharing to Files.com
An environment, health, and safety software vendor makes the software that industrial operators run their EHS programs on. Its platform covers workplace safety, chemical management, industrial hygiene, and sustainability for thousands of customers worldwide.
A company whose product is compliance gets judged by its own security posture. The vendor holds SOC 2 Type II attestation and treats that posture as part of what its customers buy. The posture collides with a fact of the business: the work runs on files exchanged with outsiders. Customers send datasets and documents in during onboarding and in steady state, and documents flow back out to them. Everything crossing the company boundary is exactly the traffic a security team most wants controlled, and it is also the traffic the business can least afford to stop.
A Three-Day Ceiling on Every External Share
To accommodate its security requirements, the vendor restricted external-sharing permissions on SharePoint and OneDrive to a three-day limit. Inside the company, nothing changed. SharePoint kept doing what it does well. Outside the company, the limit changed everything. Three days is shorter than almost any real exchange with a customer, so the tools that had carried external sharing could no longer carry it.
That left the business with a gap where a channel used to be. The lockdown needed a sanctioned channel beside it, one built for how long a real customer exchange runs. Every legitimate exchange with an outside party needed a path that stayed open for the life of the work and stayed inside the controls.
The Lockdown Was the Point
The easy fix was to loosen SharePoint back up, and the vendor never considered it. The restriction was not an accident to be undone. It was a deliberate piece of a posture the company expects to keep tightening.
So the fix had to come from the other direction. The vendor needed a channel any employee could use to send files to, and collect files from, any outside party. Every grant of access had to be temporary by design, with links that expire and accounts that shut themselves off. The controls had to be set once by security, not left to each person’s judgment on each share. And every transfer had to land in a record the security team could watch from its own tooling.
The vendor made Files.com that channel: the sanctioned path for sharing documents with anyone outside the organization.
One Governed Channel Across the Company Boundary
Files.com became the boundary of the company, and the boundary was built to be crossed safely rather than rarely.
For sending, employees use Files.com Share Links, with password protection and expiration dates carried on every link. For receiving, Files.com Inboxes collect files from outside parties who need no account and see nothing but their own upload. Customers with an ongoing exchange get their own folder and login, walled off from everyone else’s.
Access ends on its own. Links expire on their dates, and a Files.com user lifecycle rule disables any account that goes without a login for a set period. Every login, upload, and download lands in the audit log, and Files.com audit events stream over the API into the company’s Elastic SIEM, where the security team already watches everything else.
None of this displaced SharePoint from the work it is good at. It stayed the internal collaboration layer, and Files.com syncs inbound files into it, so what arrives at the boundary lands where teams already work.
Security and the Business, No Longer Trading Off
With Files.com carrying the external channel, the vendor replaced a standoff between security policy and customer exchange with a division of labor. The SharePoint and OneDrive lockdown holds without standing between an employee and a customer’s files. Outside access ends on its schedule, and external transfer activity joins the company’s existing security telemetry. The vendor also passed its SOC audits with Files.com in the environment.
Before, every new restriction on SharePoint made a customer exchange harder, and every accommodation for a customer chipped at the posture. Now the two point the same direction: the lockdown holds precisely because legitimate work has a governed place to go.
The vendor never loosened Microsoft 365 to keep files moving. It kept SharePoint for the internal collaboration it was built for, and gave everything that crosses the company boundary a channel on Files.com that was built to be governed.
Related Customer Stories
A Domain Registry Runs Self-Service Zone File Distribution for Vetted Outsiders on Files.com
The registry separated vetting and entitlement from account creation, giving hundreds of approved outsiders self-service access without putting them in its own identity systems.
Read The Story
A Database Software Company Gives Every Support Ticket Its Own HTTPS or SFTP Intake Route With Files.com
API-driven, write-only intake lets customers deliver diagnostics through their firewalls while the company keeps no standing credentials for external uploaders.
Read The Story
A Network Security Vendor Retires Box by Moving a Handful of Beta Users to Files.com
The workload was small, but absorbing it into the file-transfer environment already feeding Oracle ERP eliminated an entire external sharing surface.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes