File Hub — secure documents & file sharing
File Hub is a secure home for your company's documents inside TSync — store files in folders, control exactly who can see them, keep versions, and (in upcoming releases) share them with clients and outside people through safe links.
It is off by default. Nothing changes until an administrator turns it on.
A complete document workspace. Organize files in folders, upload through a hardened secure pipeline, rename / move / copy, select several at once, download folders or selections as a ZIP, extract ZIP archives, a folder tree, a Trash with restore, versions and locking, per-folder access rules, secure external links for files and folders, an Access & Downloads report, and a client portal. Start in Shadow mode to try it safely.
Turning it on
Open Config Center → File Hub → Settings. You'll find:
- Enable the File Hub module — the master switch. While off, the module is completely inert (no menu, no screens).
- Activation mode:
- Off — nothing changes; only this Settings page is reachable.
- Shadow — the internal staff screens work, so you can try it safely. The client portal and external links stay closed.
- On — fully active. The client portal and external sharing follow their own switches below.
- Storage backend — where files are kept. Local disk is the default; cloud options (Amazon S3, Azure, Google Cloud, MinIO) arrive in a later release.
- Advanced (only effective when the mode is On): allow external share links, enable the client file portal, and require a clean virus scan before a file can be shared.
A recommended rollout is Off → Shadow → On.
Using the files area
Once it's on, File Hub appears in the sidebar with a dashboard (mode, file count, storage used, a security-posture panel) and a Files browser:
- A personal My Folder and a company Public folder are ready automatically.
- New folder — create folders and sub-folders, navigate with the breadcrumb.
- Upload — drag files straight onto the upload box (or click it to pick them) — you can drop several at once. Each upload is checked (file type, size, content type, optional virus scan) before it is stored.
- Folder tree — a "Folder structure" panel shows your whole folder hierarchy at a glance; the folder you're in is highlighted and you can jump to any folder in one click (collapse it if you don't need it).
- List or gallery — switch the file area between a list and a gallery of thumbnails with the toggle in the top-right; the choice is remembered. In list view, sort by name, date, size or type by clicking the header.
- Preview — click the eye icon (or a thumbnail) to open images, PDFs, text, audio and video files in a pop-up, without leaving the page: images open in a gallery viewer you can step through with the arrows, PDFs and text open in a preview window, audio/video play inline. Other file types open as a normal download. Image thumbnails are real, resized previews (fast). Office documents (Word/Excel/PowerPoint) can also be previewed — see below.
- New text file — create an empty
.txtin the current folder from the "New text file" box. - Favorites — click the star on a folder to pin it; your favorites appear as quick-jump chips at the top of the folder-tree panel.
- More ways to upload — besides drag-and-drop you can add a file by URL (we fetch it securely on the server), paste an image from the clipboard straight into the uploader, or upload a whole folder (its sub-folders are recreated). The files list shows a count and total size at a glance.
- Rename, move, copy — each file's ⋮ menu lets you rename it, move it to another folder or make a copy; folders can be renamed, moved or deleted from the buttons that appear when you hover a folder.
- Select several files (the checkboxes) to act on them together: delete, move or download them as a ZIP. You can also download a whole folder as a ZIP from the folder's button or the top bar.
- Extract a ZIP — for an uploaded
.zip, choose Extract here in its ⋮ menu to unpack it into the folder; the archive's own sub-folders are recreated and every file inside is checked by the same secure pipeline. - Download any file; delete removes it (it goes to the Trash, not destroyed).
- Trash — deleted files and folders go to the Trash (in the File Hub menu). From there you can Restore them or empty the trash to remove them permanently. A deleted folder also has its own Purge button, so you can clear one folder for good without emptying the whole trash. Files on legal hold are never purged.
Allowed file types and the maximum upload size are set by your administrator in the File Hub settings. The optional virus scan rejects an infected file on upload; a clean scan can also be required before a file is shared externally (it does not block ordinary internal upload or download).
Previewing Office documents (self-hosted). If your administrator turns it on (Settings → Office document preview), Word, Excel and PowerPoint files get an inline preview too. The file is converted to a PDF on your own server with LibreOffice — nothing is sent to Google or Microsoft — and shown in the preview window. It needs LibreOffice installed on the host; when it isn't available the file simply downloads as usual.
Versions, locking, tags and search
- Open a file (click its name) to see its detail page: version history, lock state, tags and metadata.
- Versions — upload a new version any time; the older ones are kept. You can download any past version or roll back to make an earlier one current.
- Lock (check out) a file while you work on it — others can't replace, roll back or delete it until you unlock it (admins can override). A lock icon shows next to the file.
- Tags (with categories) and metadata (your own fields) help you organize and find files.
- Search (top of the Files area) finds files by name, tag and metadata — and, when content extraction is turned on, by what's written inside PDFs and text files.
Attaching files to records
Open a file and use Linked records to attach it to a business record — a lead, client, project, invoice, estimate, proposal or contract (enter the record's ID). The file then appears as a Documents panel on that record (e.g. on the lead or project page), and you can open all of a record's files from there.
Sharing files outside the company
When external sharing is enabled, open a file → Secure links to create a link you can send to someone without an account:
- View only shows the file in a viewer with a personal watermark and no download button; Allow download lets them download it.
- Protect the link with a password, an expiry date, a download limit, a recipient email, or an NDA they must accept first. When a link has an expiry date, the recipient sees it on the page ("expires on …"), so nobody is surprised by a link that silently stops working.
- Restrict by IP address — optionally limit a link so it only opens from specific IP addresses or ranges. Type them in the Allowed IPs box, comma-separated (a plain address or a CIDR range); leave it empty to allow any address. An attempt to open the link from an address that isn't on the list is blocked.
- A file must pass a virus scan (when that's required) before it can be shared.
- Email the link — send the secure link straight to its recipient by e-mail from TSync: on an active link, click the envelope button. If you didn't set a recipient email when creating the link, you're asked for one. The recipient gets the link in their inbox — no copy-and-paste needed.
- Every view and download is recorded; revoke a link instantly, or revoke all links for a file.
- Edit a link in place — from the Shared links page, change its expiry, download limit, recipient or allowed IPs, and set or clear the password, without having to revoke and recreate it.
- When you give a colleague, role or team access to a folder, they get a bell notification.
- The Shared links page lists every link with its status (active / expired / revoked / limit reached).
- Share a whole folder — you don't have to share files one by one. From the Files area, use Share folder (on a folder, or the top bar for the current folder) to create a secure link that lets the recipient download the folder — and its sub-folders — as a ZIP, with the same password / expiry / limit / IP options.
Access & downloads report
The Access & Downloads page (in the File Hub menu) shows exactly who viewed or downloaded your shared files — with the IP address, browser and time of each event, a downloads chart for the last 12 months, your most-downloaded files, and filters by event, date or email/IP. Export it to CSV any time.
The client portal & requesting files
When the client portal is enabled, your customers get a Files tab in their portal where they can browse their own folders, preview and download the documents you've shared with them, and upload files back to you into the folder they're in. Files shared with them from outside their own space appear under "Shared with you".
To collect a file from someone without an account, open a folder → Request a file and send them the link. Anyone with the link can upload straight into that folder — no login needed — and every upload passes the same security checks. You can set an expiry, a recipient email and a maximum number of uploads, and revoke the link any time.
Storage limits (quotas)
Admins can set storage quotas per company, staff member or client from File Hub → Storage quotas. When a space gets close to its limit a warning banner appears, and an upload that would go over the limit is blocked. A limit of 0 means unlimited.
Controlling who can see a folder
Open a folder and choose Manage access to control exactly who can see and use it:
- Inheritance — by default a folder inherits access from its parent, so people who can see the parent can see it too. You can stop inheriting to make a folder self-contained — then only the people you grant (plus admins and the owner) can see it.
- Grant access to a whole role (e.g. Sales) or to a specific person, at a level: View, Download, Edit/upload, Manage or Owner.
- Your personal My Folder is private to you; the Public folder is shared with company staff by default.
Admins can open Access report (in the File Hub menu) for a read-only overview of who can see which folders and where access is restricted.
Keeping documents compliant (retention & legal hold)
Admins get a Governance page (File Hub → Governance) to keep documents compliant:
- Retention — give a file a retention class (e.g. standard – 36 months) and File Hub tracks when it may be disposed. The retention sweep runs daily and archives files past their retention period — automatically.
- Legal hold — place a file on legal hold and it can't be edited or deleted by anyone (even an admin) until the hold is released. Held files are always kept, never swept.
- GDPR erasure — on a data-subject request, erase a client's files in one step; files on legal hold are kept and reported.
- Share approval & DLP — sensitive files (a confidential tag or a keyword you configure) can require approval before an external link goes live, and a legal-held file can never be shared.
Storing files in the cloud (S3 / MinIO)
By default files are kept on the server's local disk. Admins can optionally point File Hub at an S3-compatible bucket (Amazon S3, MinIO, or any S3 API) in File Hub → Settings → Cloud storage — enter the endpoint, region, bucket and keys. If the cloud config is incomplete, File Hub simply keeps using local disk (it's never an error). Once cloud is active, Migrate files to the cloud copies your existing files across safely.
Document classes: which fields each kind of document carries
Free-form tags let anyone write anything and guarantee nothing. You cannot build on them: no "contracts expiring in 90 days", and no retention rule that depends on what the document is.
A class fixes that. Under File Hub → Document classes you create a kind of document — "Contract", "Employee file" — and define its fields: each with a type (text, number, date, choice, yes/no) and, if you want, marked required.
How it behaves:
- It is checked at upload. A malformed date is refused, not silently converted: "31 February" does not become 3 March. A value outside the list is rejected. An optional field left empty is not an error.
- Classification is all or nothing. A document cannot take a class without that class's required fields — otherwise it would count as being of that kind and be silently skipped by every report built on the class.
- You can rename a label; the key does not change. Values already saved stay attached to their field.
- A class can also carry a retention period. It applies to classified documents, but it never shortens a retention already in force and never touches a document under legal hold.
An existing document stays unclassified and behaves exactly as before. Classes add a capability; they do not impose one retroactively.
Before deleting: who decides, and on what grounds
A retention date that has passed is not permission to delete. A destruction you can defend has three parts: the clock started from a real event, a person decided, and the decision is written down somewhere. Automatic pruning on a date answers none of them, and "that is how it was set" is not an answer an audit accepts.
The clock can start from an event. "Seven years after the contract ends" cannot be written as a fixed date on the day of upload — so a document can start counting from contract end, employment end, project closure or fiscal year end.
When retention expires, the document appears under File Hub → Disposition review, pending. You have three options:
- Extend — requires a duration and a reason.
- Hold (legal hold) — requires a reason. A hold always outranks a retention date.
- Approve destruction — asks for confirmation and writes the certificate.
The reason is required on the first two because "extended, no reason" is indistinguishable from "nobody wanted to decide", and that is precisely what a disposition review exists to record.
The destruction register
The certificate is written before the document is deleted, and outlives it. It records the document's name, size and checksum precisely because afterwards there is nothing left to check. You will find it under File Hub → Destruction register.
Approval and execution are separate steps. Approving is a decision; the deletion itself is irreversible, so a second check can sit between them. A certificate with no execution date means a documented intention that did not complete — you can see it and finish it, unlike a silent failure.
The daily job only queues documents. It never deletes anything by itself.
Searching inside documents, not just their names
A file nobody can find is a file nobody has. Search used to cover names, tags and the fields you fill in — never what a document actually says. So a contract you remember only by a clause in the middle of it was effectively lost.
Switch on text extraction in the module settings and the system reads the text out of your PDFs and puts it into the search. A scanned document — a photograph of paper, with no text in it at all — goes through OCR instead, so even those become searchable.
Two things worth knowing:
- Nothing leaves your server. The reading is done by programs installed on your own machine. Sending clients' documents to an outside service to be read is not something this system will do, however convenient it would be.
- It is off until you turn it on, and it needs those programs installed. Your administrator sets the paths in the settings; until then, search works exactly as it does today.
Filing uploads automatically (classification rules)
Automatic tags already existed, but a tag only helps you find a document — it does not govern one. What decides how long a file is kept, and which fields it must carry, is its class.
Under File Hub → Document classes → Rules you write sentences like "a PDF in the Contracts folder whose name contains 'contract' is a Contract". From then on retention and required fields follow automatically.
- Conditions add up. "PDFs in this folder" means both — a Word file in that folder does not match.
- A rule with no conditions at all matches nothing. Left permissive, one empty rule would file every upload in the company as the same class — which looks like it is working, right up to the day somebody notices every invoice is filed as a contract.
- If a class requires fields that the upload does not have, the file stays unclassified and the reason is recorded. A half-classified document is worse than an unclassified one, because it looks finished.
Keeping version history under control
Every save creates a version, and versions never go away on their own — which is the usual reason storage grows without anybody deciding it should.
On a folder you can set how many versions to keep. Zero means keep everything, which is how every folder behaves until you change it.
The current version is never touched — this trims history, not documents. And it refuses to trim at all when it would destroy evidence: never over a legal hold, never over a declared record, and never where the retention rule says to preserve everything.
Declaring a document a record
There is a real difference between a document, which may still change, and a record, which is evidence of something that happened and must not.
Declare as record freezes a file: no new versions, no editing, no deletion. You give a reason, and the system stores a fingerprint of the file at that moment — so years later "this is the document that was declared" is something you can demonstrate, not merely assert.
It cannot be undone. That is the point. A property somebody can switch off is not one an auditor can rely on, so a mistaken declaration is corrected by superseding it with a new document, exactly as a paper archive would.
Reviewing links that are still open
An external link can already be given an expiry date, a watermark and an approval step. What none of that answers is whether a link that is still live is still wanted.
Set a review interval in the settings and each share has to be re-confirmed periodically. You see the ones due, and for each you either keep it or revoke it — with a note.
- A link that has never been confirmed counts as due, timed from when it was created. Otherwise the link set up once and forgotten — the very one that leaks — would never appear in the review that exists to find it.
- The system never revokes anything by itself. Cutting off somebody's access because a timer ran out would break a working handover with no warning. It brings the list to you; the decision stays yours.
- Off until you set an interval.
Signing documents (e-signature)
When e-signatures are enabled, open a file → Sign this document to sign it with a touchpad or mouse. Before signing, the signer reads your data-confidentiality terms (which you edit in File Hub → Settings) and ticks a required acceptance box. Each signature records the signer's name, email, IP address, time and a fingerprint of the exact document — and the document is locked so it can't be changed afterwards. A signature certificate shows all of this and warns if the document ever changes. You can also send a sign link to someone without an account (open a file → Secure links → Request signature).
How your files are protected
- Files are stored privately — they are served only through TSync's access-controlled screens, never from a public web address.
- Access is permission-controlled and respects your company/branch setup, so each team only sees what it should.
- Every change is recorded in the audit log.