IntroductionLast updated: 6 August 2026
JCOGS Secure File Service - Access provides a governance and access-control layer for sensitive file areas in ExpressionEngine.
In simple terms, it helps you define secure enclaves, decide who can use them, and control what each role is allowed to do.
An enclave is a named secure file area linked to a qualifying above-webroot upload location, with explicit access rules for operations such as listing, upload, download, and deletion.
Access also gives developers a practical way to use above-webroot file locations while keeping familiar EE Files and template tag workflows.
This keeps security decisions structured and repeatable, rather than relying on one-off permission changes.
Design note
SFS Access is designed to strengthen security without replacing familiar EE file workflows. Above-webroot location support and policy controls work together, so teams can keep moving while sensitive access remains controlled.
Who is it for?
SFS Access is for ExpressionEngine teams that need to store files more securely and with greater control over who can access them.
It is especially useful where file sensitivity varies and access decisions need to stay consistent over time.
- Site owners and managers who need stronger governance for confidential or regulated files.
- Administrators who want role-based access control that is easier to maintain over time.
- Content teams who need predictable access outcomes and less confusion around file permissions.
- Developers who want security controls that fit practical EE operations.
If your current approach relies on broad, manually adjusted permissions, SFS Access provides a more reliable model.
Why it matters
Many security problems happen gradually: permissions become too broad, exceptions accumulate, and teams lose confidence in who can access sensitive files.
SFS Access addresses this in two practical ways: it supports secure above-webroot file location use, and it makes access governance explicit.
You define enclave boundaries, assign role capabilities, and let policy checks decide whether each operation is allowed.
- Stronger file protection by using qualifying above-webroot locations for sensitive content.
- Reduced permission drift through clear role-based rules.
- More consistent decisions across teams and environments.
- Faster incident response when restrictions need to be tightened quickly.
- Clearer accountability because access outcomes are based on policy, not ad hoc overrides.
The result is stronger protection with less operational friction.
How SFS Access Fits into the SFS Suite
SFS Access can run on its own and already provides secure above-webroot location support with policy-controlled access operations.
It can also be combined with companion add-ons in the SFS suite:
- SFS Vault adds encrypted-at-rest storage and a stricter secure-root storage model.
- SFS Gateway adds controlled ways to share access to secure files outside the core team.
Starting with SFS Access alone is a practical path for many sites. You can then add Vault or Gateway when your storage and sharing requirements expand.
Design note
Keeping governance, storage hardening, and sharing controls as separate but aligned components gives teams flexibility. You can deploy stronger controls in stages without redesigning your whole file workflow at once.
Trial and Licensing Overview
SFS Access includes a 7-day trial period for unlicensed installations, so you can validate setup and policy behaviour in a safe staging environment before purchase.
During the trial, focus on practical checks:
- Create one or more enclaves (named secure file areas) from suitable above-webroot EE upload locations.
- Test role-based controls for listing, upload, download, and deletion.
- Confirm authorised users can work smoothly while unauthorised actions are blocked.
For production use, install a valid licence and keep your deployment aligned with your organisation's governance requirements.
Store listing: expressionengine.com/add-ons/jcogs-sea-access
Documentation: jcogs.net/documentation/jcogs_sfs_access