Skip to main content

Resource Innovations Makes Temporary External Access the Default on Files.com

Fixed expirations, inactivity rules, security groups, and bulk provisioning keep a constantly changing partner population governable without relying on IT’s memory.
Resource InnovationsFiles.com

Resource Innovations is an energy transformation firm that designs and runs energy-efficiency and demand-side programs on behalf of utilities. Its work brings together employees and outside partners who need to exchange files for the life of each program.

Every one of those programs is temporary by design. A utility commissions it, Resource Innovations staffs it with its own people and outside partners, and eventually the program winds down. The file exchange behind the work follows the same rhythm. Each program brings contractors, partner firms, and utility staff who need to move files, and each program eventually stops needing them. A business built on engagements that start and end on someone else’s schedule can never have a stable population of external users, so Resource Innovations was always going to face a question most companies never have to ask at this scale: who removes all that access when the program ends?

A Partner Population That Swings With Every Program Cycle

The numbers show how unstable the population really is. Over the year before June 2024, Resource Innovations’ file-exchange user population ranged between 175 and 253. Dave Monroe, the company’s VP of Technology, has described the pattern as random by nature: a program team decides the exchange is its solution, needs twenty users for six months, and then the program ends. By his own account, user growth is not something he will ever be able to predict.

Arrivals were never the problem, because creating an account is easy work. Departures were. When a program closes, noticing is nobody’s job. The accounts created for it simply remain: partner credentials into client program data, held by people who no longer need them, invisible until someone goes looking. For years the exchange ran on a self-hosted FTP server, where an account existed until an administrator deleted it, and deleting it meant a central IT team remembering which program’s contractors were finished.

That approach cannot keep pace with structural churn. Turnover is driven by program starts and ends across many concurrent engagements, on schedules set by utilities and regulators rather than by IT. A removal process that depends on human memory falls behind by exactly the amount the business grows.

Making Expiration the Default State of an Account

The fix had to invert the default. An account had to carry its end date from the day it was created, so that removal never depended on anyone’s recall. Access had to attach to the structure of a project rather than to individuals. The live population had to be verifiable against real logins. And all of it had to be workable in bulk, because users arrive twenty at a time.

Resource Innovations selected Files.com as its client and partner exchange and wrote those requirements into platform policy. Files.com became the layer that ends access, so that no person has to.

Every account on the site was created with an expiration date: one year for employees, six months for external users. Alongside it, Files.com’s inactivity rule disables any account that has not logged in for 45 days. The two policies cover both ways a program-scoped user goes stale: the engagement running out, and the person quietly stopping work before it does. Either way, Files.com closes the access on its own.

Access itself was granted only through Files.com security groups, never to individuals. A single project can carry more than 20 groups across its nested folder tree, keeping access legible by program: reviewing a project’s access means reviewing its groups rather than hunting through individual grants.

For the volume, the team scripts against the Files.com REST API. PowerShell jobs driven by CSV files create users, assign them to groups, and update enable and expiration flags in bulk when dates need to change. Standing up a program’s twenty users is one pass rather than twenty tickets. Files.com’s last-login reporting then shows who is actually active, turning periodic access reviews into checks against data instead of exercises in recollection.

Access That Ends Without Anyone Remembering to End It

With those policies in production, Resource Innovations replaced account cleanup that depended on memory with access that ends by rule. Program-scoped accounts now reach their expiration dates whether or not anyone recalls why they were created, while accounts that go quiet are disabled after 45 days. The gap between a program ending and its access ending is bounded by policy, not by how long it takes someone to notice.

Periodic reviews now confirm the policy against last-login data instead of performing the cleanup themselves. When the next program begins, its users are created, grouped, and given end dates in one bulk pass, so growth in programs no longer means proportional growth in accounts someone has to track by hand.

Governed for the Programs Nobody Has Predicted Yet

Today the population still swings the way it always has. Programs keep starting on utilities’ schedules and ending on regulators’, and Resource Innovations still cannot predict its own user growth. What changed is that the unpredictability stopped being a governance problem. An administrator once had to remember which program’s contractors were done. Now every account on the Files.com site is born with its end date, and the ones that go quiet are shut off before anyone asks. Resource Innovations did not get control of external access by predicting the churn. It made prediction unnecessary: on Files.com, temporary is the default state of an account, and a program that ends takes its access with it.