Skip to main content

Jockey Replaced Microsoft SharePoint With Files.com for Auditable Design Delivery to Factories With Limited IT Support

Read-only accounts and always-on access logs kept garment plans on Jockey's sanctioned path and every download on the record.
JockeyFiles.com

Jockey International invented the brief. The company that began in 1876 making wool socks for lumberjacks sold the world's first briefs at a Chicago department store in 1934, and today it remains family-owned, headquartered in Kenosha, Wisconsin, and the number one underwear and intimates brand in US department stores.

Jockey designs its garments in-house. It makes almost none of them itself. Production runs through a network of contract manufacturers concentrated in Asia and Central America: factories Jockey does not own, run by vendors Jockey does not employ. Every garment in that network begins as a set of spec sheets, the plans that tell a factory exactly what to cut and sew. Those plans are the company's intellectual property. And for Jockey to sell a single garment, they have to leave the company.

Spec Sheets for Factories With No IT Staff

A vendor producing a garment needs the spec sheets for that garment. Nothing about the exchange is exotic: files go out, a factory downloads them. What made it hard was who sits at the other end. Jockey's vendors are in the Philippines and across the Asia-Pacific region. Many have no IT staff at all, and technical detail has to cross a language barrier. A channel that required specialized software or configuration walkthroughs in a second language was a non-starter.

The stakes ran the other way. The plans are the product before the product exists. The risk Jockey carried was a design traveling a path the business never chose, and a harder version of the same risk behind it: when a question arose about a specific plan, who accessed it, when, and from where, Jockey needed a forensic answer. That kind of answer only exists if the record was being kept before anyone thought to ask.

So the channel had to be two things at once: the simplest possible workflow for the least technical party in the chain, and the most controlled workflow Jockey could run. Jockey found that balance in read-only SFTP accounts on Files.com, with an always-on record of every file access.

SharePoint Couldn't Be Secured to the Level the Plans Demanded

On paper, a SharePoint library looks like the answer: put the documents in one place, give each vendor access, and let them download. Jockey tried it, and Tim Anderson, the senior engineer who runs the company's file exchange infrastructure, moved the workload off it.

We tried SharePoint for a bit. There's just no way to properly secure it to the level that secure FTP can provide.
Tim Anderson, Senior Engineer, IT Infrastructure, Jockey

What the workload needed was the shape of a shared document library delivered on the security model of secure FTP: accounts that can do exactly what they were created to do, and a record of every access detailed enough to reconstruct a transfer after the fact. Files.com provided that channel.

Read-Only Access Over Standard SFTP

On Files.com, a vendor connects over plain SFTP, a protocol any standard transfer client already speaks, and downloads the spec sheets for the garments it is producing. The account it connects with is dedicated to exactly that job. Files.com folder permissions scope it to read-only access, so a vendor cannot upload, alter, or delete anything, and a plan cannot move any way the business did not decide it should move.

Underneath that simple workflow, the Files.com audit log records every action: which account pulled which file, at what time, from which address. There is nothing to enable per transfer and nothing to remember to switch on. The log runs before the question exists.

Who Pulled Which File, When, and From Where

With Files.com as the sanctioned channel, Jockey replaced a portal it could not secure with a workflow its least technical vendors handle without help, and gained the record SharePoint could not produce.

  • Distribution stays on the sanctioned path. A vendor's account can only read, so nothing happens to a plan outside how the business decided to transmit it.
  • Access questions get forensic answers. When Jockey needs to know who pulled a plan, the log already holds the file, the time, and the source.
  • Vendors with limited IT capability are served without technical back-and-forth. A vendor needs a credential and a standard SFTP client, and nothing more.
They did pull this file at this time. This is where they did it. I can't turn it on after the fact.
Tim Anderson, Senior Engineer, IT Infrastructure, Jockey

Simple for the Factory, Governed for Jockey

For a company whose product exists as a document before it exists as a garment, the governed channel had to come first.