Hampton Roads Transit Ends Shadow IT by Making Files.com as Easy as Dropbox and Google Drive
Hampton Roads Transit (HRT) is the regional public transportation provider for southeastern Virginia, serving Chesapeake, Hampton, Newport News, Norfolk, Portsmouth and Virginia Beach. It runs local and express bus service, ADA paratransit, passenger ferries across the Elizabeth River, and The Tide in Norfolk, Virginia's first light rail line.
An operation like that runs on more than vehicles. Engineering, marketing, IT and HR all exchange files with people outside the agency: contractors, vendors, partner organizations, and the public itself, since as a public body HRT answers FOIA requests for its records. Nearly every department regularly needs to put a file in an outsider's hands, and IT had no sanctioned way for them to do it. Replacing those workarounds would depend on giving employees a governed path as convenient as the consumer tools they already knew.
Files Left the Agency Through Personal Dropbox Accounts
So departments solved the problem themselves. Files went to outside parties through personal Dropbox accounts, through Google Drive, and as email attachments, whichever tool was closest at hand. Engineering, marketing, IT and HR each had their own version of the workaround.
Every one of those paths sat outside the agency's control. A file shared from a personal Dropbox account belonged to that account, not to HRT. Nobody in IT could see that it had been sent, take the access back when the employee left, or produce a record of the exchange afterward. At a private company that is a security gap. At a public transit authority, whose files include HR data and the material that answers public-records requests, it is agency records moving through accounts the agency cannot see, audit, or reclaim.
The arrangement persisted for the reason shadow IT persists everywhere: the consumer tools were genuinely easy, and a policy banning them would not have moved a single file to a vendor. Any sanctioned replacement would compete directly with tools that take two clicks, and if it lost that comparison, people would quietly keep the unsanctioned ones.
The Replacement Had to Be as Easy as the Tools It Displaced
That shaped the requirements Afonso Alves, HRT's Manager of Cybersecurity Services, set for a fix. Employees had to sign in with the Azure Active Directory credentials they already used, not another password to forget. Sending a file to an external vendor had to be exactly the motion people already knew: log in, upload, send. The recipient could not be asked to install anything or create an account. And underneath that ease, IT needed everything the consumer tools lacked: accounts tied to the corporate directory, each department scoped to its own data, and a record of every action.
HRT selected Files.com to be that sanctioned path.
Behind the Agency's Login, With a Link Anyone Can Open
Files.com became the one governed way HRT's departments exchange files with the outside world, sitting behind the login employees already had. Single sign-on authenticates users against the agency's Azure Active Directory, and SCIM provisioning keeps the user list mirrored to it: accounts are created from the directory and deactivated with it. Nobody in IT sets up file-sharing users by hand, and when an employee leaves, their access ends with their directory account. That is the exact failure a personal Dropbox account made permanent.
Folder-level permissions keep each department in its own space, so a team can work with its own outside partners without gaining a view into anyone else's data. For sending, users create Files.com Share Links: an employee signs in, uploads a file, and sends a link the recipient opens in a browser, with nothing to install and no account to create. It is the two-click experience the consumer tools offered, with the difference that every link comes from an identified agency user and every access is logged.
Files.com also streams its event and authentication logs to Rapid7, HRT's security monitoring platform. The file sharing that the security team once could not see at all is now telemetry it watches alongside every other system.
Adopted Across the Agency, and Trusted with FOIA
With Files.com in production as the sanctioned path, HRT replaced ad hoc consumer sharing with a platform its departments actually took up.
- Engineering, marketing, IT, HR, finance and ERP teams all exchange files with outside partners through Files.com, so adoption spread across the agency instead of stalling in the department that stood it up.
- HR sends the agency's FOIA responses through Share Links, so the delivery of public records is itself on the record.
- Personal Dropbox accounts, Google Drive and email attachments are no longer how files leave the agency.
“The technology is way better than I expected, and many departments are using it.”
The same SSO and permissions model let HRT add departments without building a custom rollout for each one.
The Easy Path Is Now the Governed Path
Today, when someone at HRT needs to get a file to a contractor, a vendor, or a records requester, they do what they always wanted to do: sign in, upload, send a link. What changed is everything around that moment. The login is the agency's own. The transfer is logged, and the security team sees it in the same console as the rest of its telemetry. The file never touches an account HRT does not control.
The consumer tools did not lose at HRT because a policy banned them. They lost because Files.com gave every department a sanctioned path that was just as easy to use, and shadow IT only ends when the sanctioned path wins on convenience.
Related Customer Stories

Transportation & Logistics
AAA Northeast Replaced Progress WS_FTP Without a Big-Bang Cutover
The migration preserved partner workflows with a hostname-and-credential change while Files.com made encryption, retention, identity, and auditing enforceable.
Read story →
Transportation & Logistics
FlightSafety Moves Oversized, Confidential Aviation Documents Beyond Email With Files.com
Each outside party signs in through a branded browser experience and reaches one permission-scoped folder through an account that expires on schedule.
Read story →
Transportation & Logistics
Need It Now Delivers Retires Its In-House File Server for Unattended SFTP Dispatch
One business-side manager moved client-isolated dispatch feeds to Files.com, where nightly manifests have arrived for three years without daily intervention.
Read story →