Skip to main content

TraceLink Replaced Dropbox, Egnyte, and ShareFile With Files.com—Without Moving Its S3 Data

Remote Server Mounts gave TraceLink a repeatable, Okta-managed access pattern while its live S3 buckets remained the storage of record.
TraceLinkFiles.com

TraceLink operates a global digital network for pharmaceutical supply-chain traceability, serialization, and regulatory compliance, connecting drug manufacturers, distributors, and dispensers.

That is the product. Behind it sits a global company with its own internal estate to run. TraceLink's internal file storage of record is a set of AWS S3 buckets, holding everything from Workday HR documents to device inventory data out of Intune. Every department that needed to store, share, or exchange files ultimately needed a governed way to reach that storage.

Three Sharing Tools, and None of Them Fronted the Storage

What had grown up instead was a sharing layer split across three separate tools: Dropbox, Egnyte, and ShareFile, all running in parallel. Three tools meant three permission models to administer and three sets of accounts to create, update, and remove, tool by tool, none of them driven by Okta, the company's identity source of record. The sharing layer and the storage layer were two different worlds.

The cost landed on IT every time a department needed governed file access. Each request was a fresh one-off problem: which of the three tools, which accounts, and how the result would relate, or fail to relate, to the storage of record. There was no pattern to apply. Every team's file access was solved from scratch.

The S3 buckets could not simply be emptied into a new platform, because they were the storage of record for live systems; migrating the data meant re-pointing everything that wrote to it. And replacing three sharing tools with a fourth that carried its own standalone user directory would have deepened the identity problem rather than fixed it.

So the requirements were clear before any product was. TraceLink needed a single sharing layer that fronted the existing S3 buckets in place, took identity and account lifecycle from Okta, and permissioned by group so each department could own its own space. TraceLink selected Files.com to be that layer.

The Buckets Stay Put, and Files.com Goes in Front

Files.com became a governance layer in front of storage TraceLink already ran, not a new place for the data to live.

Using Files.com Remote Server Mounts, TraceLink's IT team surfaced the existing S3 buckets as folders on its Files.com site. Every operation performed through Files.com passes through to S3 in real time, and the buckets remain the storage of record. Nothing migrated, and no second copy of the data was created.

The mounts authenticate through short-lived, tightly scoped STS roles rather than long-lived IAM access keys.

Identity stayed exactly where it belonged. Okta drives single sign-on into Files.com, and SCIM provisioning and deprovisioning keep accounts in step with the directory: a user provisioned in Okta gets a Files.com account with the right group memberships, and a user deactivated in Okta loses file access without anyone touching a second system. Consolidating onto Files.com added no fourth user directory to maintain.

Group-based permissions then mapped each department onto its own folders. The rollout ran department by department, with requirements gathered per team, and the folder and permission pattern was designed from the start as a boilerplate: the structure built for the first teams was meant to be applied again, unchanged, for every team after them. What had been solved from scratch for each team could now be repeated from one team to the next.

Three Tools Retired, One Pattern That Repeats

With the Files.com layer in production, TraceLink retired Dropbox, Egnyte, and ShareFile and replaced all three with a single governed platform over the storage it already ran.

IT now administers one permission model instead of three, while file access follows Okta's account lifecycle rather than separate manual account updates. Each department joins the same governed file-sharing model without disrupting the live systems that continue to write to S3.

Consolidation Without a Migration

The larger point is what the consolidation did not require. Files.com never replaced TraceLink's storage; it replaced the three tools standing between people and that storage. The sharing estate collapsed to one governed layer, and the data never moved.