Skip to main content

An Insurance Group's Shared-Services Team Uses Files.com Child Sites to Delegate Control Without Giving Up Governance

Files.com child sites let division teams manage distinct SFTP and browser workflows while the group's shared-services team retains group-wide oversight.

A Fortune 500 insurance group underwrites specialty insurance through a decentralized collection of specialist operating companies.

The structure is deliberate. The group runs a model built on narrow and deep expertise: each operating company is designed to know its market better than anyone else, with decision-making authority placed close to the customer and the risk.

A shared-services organization holds the corporate side of that together. It provides data processing, accounting, administrative, and professional services to the group's insurers, and some affiliated entities have no employees of their own, running entirely on shared-services staff. The organization stood up its own independent IT department, taking over infrastructure that had previously been run out of another subsidiary. Its mandate was to provide IT, including file transfer, to operating centers across a group of more than a dozen divisions: specialist companies that were designed, on purpose, to have almost nothing in common about how they work.

One IT Team, Divisions With Nothing in Common

The first two divisions that needed file transfer made the problem concrete.

The group's newest underwriting subsidiary writes employer stop-loss coverage for self-funded employers. Its hospital partners send large files carrying HIPAA-regulated patient information, and the new division needed a compliant way to take them in.

An automotive services division has administered GAP plans and vehicle service contracts for automobile dealers for decades. Its file work looks nothing like a PHI intake: warranty documents exchanged back and forth with automotive customers, on no fixed schedule, with counterparties who connect through a browser rather than an SFTP client.

Serving both from one flat environment would have forced a bad trade. Either division staff get broad administrative credentials over an environment that also holds another company's data, with hospital PHI sitting alongside warranty paperwork, or the small shared-services team operates everything itself: every user account, every folder, every permission change, for every division. The group launches new operating companies regularly. A model where central IT hand-brokers each division's file transfer does not survive division three, let alone a dozen or more.

And the governance could not loosen to compensate. These are regulated insurers whose intercompany service arrangements appear in state insurance department examination reports. The shared-services team needed each division to run its own file exchange, and it needed to answer for all of it.

What the Platform Had to Be

Whatever the shared-services team deployed had to give each division a genuinely separate environment, with its own branding, its own administrators, its own users, and its own compliance posture, so that a HIPAA-covered intake for one division imposed nothing on a division trading warranty files. It had to speak SFTP to hospital systems and hand a browser link to a warranty customer. And it had to stay one platform, with one place where corporate IT holds oversight and a complete record of every file.

The shared-services organization selected Files.com to run the group's file exchange on that model.

A Separate Site for Every Division

On Files.com, the shared-services team operates one platform that presents each division with its own site.

The stop-loss division went first. The team created a Files.com child site for the division: a fully separate site under the corporate parent, carrying the division's own branding, users, and administrators. The division piloted the intake with a single hospital partner, then widened it to more than a dozen hospitals, each delivering PHI-bearing files over SFTP into the division's own site under a HIPAA Business Associate Agreement.

The Files.com Agent can deliver those files to the group's internal storage over an outbound-only connection. Because the hospitals connect to the Files.com endpoint rather than the storage behind it, they can keep using the same connection as the shared-services team moves its back-end infrastructure from on-premises storage to Azure.

A second child site followed for the automotive services division, carrying an entirely different workload: warranty files sent to and received from automotive customers through branded Files.com Share Links, in the browser, with no account or software on the other end.

Each site has its own administrators. A division manages its own users, access, and use cases, and cannot see or reach a sibling division's site, because administrative credentials stop at the site boundary. Corporate IT retains oversight of every site from the parent.

The shared-services team configured the deployment in-house, building the connections, workflows, service accounts, and folder structures with its own team. And every file on every site carries its own audit history: who uploaded it, who moved it, who downloaded it, and when. The group knows who owns a regulated file at all times and where it has been.

What Changed for the Group

With both child sites in production, the shared-services organization replaced the choice between one undifferentiated environment and a hand-operated central service with a standing pattern: each division gets its own governed site. Bringing on the next division is a child site, not a platform project.

The shared-services team no longer stands between a division and its own file transfer. It does not create the division's users, field its access changes, or administer its workloads. It governs them.

File Transfer That Runs the Way the Group Runs

The group built itself as a collection of specialist companies with decision-making placed close to the customer, and today its file transfer works the same way. When the stop-loss division takes in a hospital file, or the automotive division sends a warranty document to a customer, the division is operating its own Files.com site, under its own name, run by its own people. The shared-services team that answers for the group's governance can see all of it without operating any of it. The team never had to choose between delegating file transfer and controlling it: on Files.com, a small central IT team serves a group of independent companies by handing each one its own site and keeping one set of controls over everything.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes