Skip to main content

An Insurance Distribution Firm Puts Governed Self-Service Access in Front of Its 10-Year S3 Call Archive With Files.com

SSO and SCIM, a play-only role, and metadata search give approved staff a searchable path to millions of recordings without moving them, with every access tied to a named user and streamed to the firm's SIEM.

A US insurance distribution firm delivers insurance, risk management, and employee benefits to clients nationwide. A meaningful part of that business happens on the phone. One division sells individual health plans and Medicare coverage through enrollment centers and a network of thousands of agents, and phone enrollment brings those recorded lines into the scope of the firm's PCI controls.

Compliance rules require the firm to keep call recordings for ten years. So the business builds, one call at a time, an archive of millions of recordings that falls inside the company's compliance scope. The firm used Files.com to put governed, self-service access in front of that existing AWS S3 archive without moving or duplicating a recording, under the same controls that govern the archive itself.

A Decade of Recordings the Business Needed to Reach

Recordings start in Five9, the firm's contact-center platform, and in Zoom. Both keep a recording for 60 days. After that, each call moves into the firm's own AWS S3 buckets, much of the volume in cold storage, where it sits for the rest of its ten-year retention period.

The people who needed those recordings had no self-service way to reach them. When a state regulator or an insurance carrier raises a complaint, operations leaders have to go back to the original calls, listen, and analyze what was said, on a deadline. But the archive was raw object storage, with no interface a business user could touch.

Every retrieval meant asking IT, and a time-sensitive complaint review waited on someone with AWS access to pull a file out of cold storage.

The firm also set a requirement for the access layer itself. PCI requires that access to in-scope stored data be authenticated, limited to the people who need it, and logged, so the firm wanted a demonstrable wall in front of the recordings, with a record of every access behind it that its assessors could review.

The Archive Could Not Move

The obvious fixes were all closed off. Migrating the archive onto another platform meant re-platforming millions of files under ten-year holds and paying to store a decade of audio twice, against cold-storage economics that existed for a reason. Ten years of historic calls stay exactly as recorded for the life of the retention period, so the controls had to sit in front of the archive rather than inside it. And handing non-technical staff direct access to the buckets was never on the table.

So the requirement was precise: an authentication wall in front of storage the firm already owned, self-service search and playback for approved staff, permissions granular enough to let someone listen without letting them download, and a per-access log that both the security team and a PCI assessor could consume. All of it without moving or duplicating a single file.

The firm chose Files.com to be that wall.

A Window Into Their Own AWS

Files.com became the governed front door to storage the firm already owned. Nothing migrated, and nothing is stored twice.

Using Files.com Remote Server Mounts, the firm connected multiple S3 buckets, including the cold-storage-backed archives, into a single Files.com site. Every operation passes through to the bucket in real time, so the recordings stay in the firm's storage under the firm's retention rules without giving staff direct AWS access.

Staff sign in through Microsoft Entra ID with SAML single sign-on, and SCIM provisioning keeps accounts matched to the directory, so access follows employment rather than a manually maintained user list. Group-based folder permissions decide who can reach which recordings, and a play-only role lets a reviewer listen to a call in the browser without taking a copy of it.

Finding a call matters as much as gating it. The Remote Server Mount metadata index lets staff search across an entire mounted bucket, including one holding hundreds of thousands of files, instead of needing to know a path in advance.

And everything is on the record. Every login and every access lands in the Files.com audit log and streams to the firm's SIEM, Google SecOps, where the security team watches it alongside the rest of the estate. Files.com's PCI Attestation of Compliance and responsibility matrix feed the firm's own annual assessments.

Self-Service Retrieval Inside the Assessed Controls

With Files.com in production over the buckets, the firm replaced an archive only IT could touch with a governed retrieval path under the same controls that govern the archive itself.

  • The Files.com-over-S3 configuration stands as the authentication wall and audit-logging layer over the archive, and it is part of the controls the firm presents in its annual PCI assessment.
  • Operations staff across multiple teams now retrieve and play recordings themselves. A state or carrier complaint review starts with a search, not with a request to IT.
  • Every retrieval is tied to a named, SSO-authenticated user, scoped by permission, and streamed to the SIEM, so who accessed which recording is a single lookup.
  • The archive never moved. It stays in the firm's own buckets, at cold-storage prices, with nothing paid twice.

The configuration also compounds. Bringing another bucket or another team under the same wall is a mount and a group permission, with the single sign-on, roles, and SIEM feed already in place, and the firm has since extended the same setup to additional divisions.

The Access Layer Is the Compliance Posture

Today, when a complaint lands, the reviewer signs in with company credentials, searches the archive, and presses play. What used to open with a request to IT, against a regulatory deadline, now opens with the analysis itself.

Behind that login, Files.com is doing the control work: a decade of in-scope recordings can be reached only by named, authorized people, one recording at a time, with every access written to the record. The firm never migrated the archive and never handed a business user an AWS credential. A regulated archive does not have to move to be governed. The firm made the access layer part of its compliance posture, and Files.com is that layer.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes