Spencer Gifts Replaces a Manual QA Relay with Browser-Only Vendor Access on Files.com
Spencer Gifts is the specialty retailer behind two of the most recognizable banners in North American retail: Spencer’s, the novelty and pop-culture chain, and Spirit Halloween, which opens roughly 1,500 seasonal locations across the U.S. and Canada each fall. Much of what fills those stores is Spencer’s own product. Costumes, décor, collectibles, and novelty items are designed and quality-tested in-house and manufactured by outside vendors.
That model has a consequence for quality control: some of the people inspecting Spencer’s products work for other companies. Vendors fill in product inspection sheets, and Spencer’s warehouses review and approve them, with a sheet passing from one warehouse’s review to the next. The vendor side of that loop will never appear in Spencer’s Active Directory, and those partners cannot be given accounts on Spencer’s internal servers. Every internal tool the QA team might use to run the loop sits behind an identity boundary that half the participants can never cross.
An Inspection Loop the Inspectors Couldn’t Reach
For years the loop ran on an internal shared drive. The drive worked for the warehouses and was unreachable for the vendors, so every round of inspection depended on someone inside Spencer’s bridging the gap: getting a sheet out to the vendor, collecting the completed version, and putting it back where the next warehouse would look. The review chain could only move as fast as the people carrying files across the boundary, and that carrying was recurring manual work attached to every inspection.
The content of the sheets raised the stakes on any shortcut. Inspection sheets document shipping and quality problems with specific products. That is information meant for the warehouses handling those products and no one else, so loosening access to make the vendors’ lives easier was never on the table.
The Constraints That Ruled Out Every Easy Fix
Each obvious fix failed a test.
Internal accounts for the vendors were out: the partners are not in Active Directory, and access to internal servers requires that identity. Posting the files behind a simple password-protected link was out too. The security team required named users, a known headcount on the data, and logs that could answer who did what, and an open link provides none of that. And rebuilding the process in some new tool was out, because the inspection sheets are macro-enabled Excel tracking templates, with formulas and values the warehouses already rely on. Nobody was going to rewrite those workbooks or risk breaking their macros.
So the fix had a clear specification before it had a name. It had to hold accounts that live entirely outside the corporate directory. It had to limit those accounts to a browser, with every other protocol shut off. It had to confine each vendor to its own folders, log every action in a record the team could query later, and let both sides keep working in the exact macro-enabled workbooks already in use.
Spencer’s selected Files.com to be that exchange point.
With the workflow on Files.com, Spencer’s replaced a process that ran on internal staff hand-carrying files with a review loop both sides work in directly.
Web-Only Accounts, Scoped Folders, and the Same Workbooks
Files.com gave Spencer’s a governed exchange point that belonged to neither side’s internal network and that both sides could reach.
Each external inspection partner got a named Files.com account created with a web-only protocol restriction: the account worked in a browser and nowhere else, with SFTP and every other connection method turned off. Per-folder permissions confined each account to its own review and return folders, mirroring the structure the warehouses worked in, so a returned sheet stayed attributable to the vendor who sent it and landed where the next reviewer expected it.
The workbooks came across untouched. Through Files.com’s Office 365 web editing, a vendor could open a macro-enabled inspection template in the browser, fill it in, and return it, while the warehouses could keep reviewing in the same templates they had always used.
The security requirement stopped being a policy someone enforced and became a property of the platform: a fixed set of named accounts, a known headcount on the folders, and Files.com activity logs recording every action. Answering who touched what became a lookup.
The Review Chain Runs Without a Go-Between
Vendors now submit and return inspection sheets themselves. No one inside Spencer’s ferries files between the shared drive and the outside world.
Adding the next outside reviewer is an account and a folder permission, not an identity project. The pattern holds for any partner who will never hold a Spencer’s login.
The Directory No Longer Decides Who Can Take Part
The line between inside the directory and outside it used to decide who could do the work; now it is a permission setting on a folder. Spencer’s got an accountable, least-privilege QA workflow with partners it will never employ, without standing up a single account on its internal systems and without rebuilding the tools the work runs on.
Related Customer Stories
Retail & Consumer
Barnes & Noble Moves 30 GB Vendor Files With Files.com—Without Vendor Accounts or a New Repository
A thin, governed transfer layer now carries about a terabyte a month to changing external partners while existing storage stays in place.
Read story →
Retail & Consumer
Marc Jacobs Retired Its FTP/SFTP Servers One Workload at a Time With Files.com
Amid simultaneous ERP and cloud migrations, Marc Jacobs kept dozens of live retail flows moving while completing its data-center exit.
Read story →
Retail & Consumer
One Counterparty at a Time, Jockey Moves Off Its Progress Ipswitch FTP Server With Files.com
Files.com runs alongside the old endpoint, letting Jockey remove workloads it controls while vendors and remaining third parties move on their own schedules.
Read story →