Add-on Documentation from JCOGS Design

Evaluating and Buying - GuidanceLast updated: 6 August 2026

Trial Evaluation Plan

SFS Access includes a 7-day trial period so you can test the add-on fully before purchase. The following plan makes the most of the trial time by covering the key areas that matter for a production deployment decision.

Day 1–2: Installation and basic setup

  • Install SFS Access and confirm all Control Panel panels load correctly.
  • Identify where you plan to store your above-webroot upload locations.
  • Configure Global Settings to match this choice and confirm Secure Root health.
  • Create a test eligibility pool and a test enclave.

Day 3–4: Role and permission testing

  • Assign test members to each built-in role: Viewer, Contributor, and Enclave Admin.
  • Confirm that allowed operations succeed and denied operations are blocked as expected.
  • Use Effective Access Check to validate decisions for each role.

Day 5: Baseline mode governance testing

  • Test the enclave lock and unlock flow.
  • Deactivate and reinstate a membership and confirm outcomes.
  • Review Security Activity Log entries produced by your test actions.

Day 6: OTP Pro enhanced operation and SFS companion add-on testing

  • Test one high-risk admin change that uses OTP Pro and confirm the verify-then-resume flow works.
  • Check that companion-only actions appear when companions are installed and healthy.
  • Check that those actions are hidden or blocked when companion prerequisites are unavailable.

Day 7: Review and decision

  • Decide whether the add-on does what your site needs in day-to-day use.
  • Review any questions or issues that arose during testing.
  • Contact support@jcogs.net if you need clarification before purchase.

Moving from Trial to Production

When you are ready to move from trial to production, follow these steps to ensure a smooth transition.

  1. Purchase a production licence from the EE Store listing.
  2. Apply the licence key to your domain within your EE Store listing page. This removes trial restrictions and activates full production mode.
  3. Carry out a final governance review before going live:
    • Confirm all eligibility pools are correctly scoped.
    • Confirm all enclave assignments and upload locations are as intended.
    • Confirm role permissions reflect your least-privilege decisions.
    • Confirm membership assignments are accurate and limited to authorised users.
  4. Run Effective Access Check for a sample of members across different roles to confirm production access outcomes match your governance plan.
  5. Remove any test data used during evaluation that should not be present in a live environment.

If you installed companion add-ons (OTP Pro, SFS Vault, SFS Gateway) during evaluation, confirm their production licences are also in place before launch.

Adding Companion Add-ons

SFS Access is the core of the SFS suite. You can run it on its own, then add companions only where they solve a clear security or delivery need.

When SFS Access alone is sufficient

SFS Access on its own is often enough when you need strong role-based file access control for above-webroot storage. It covers enclaves, memberships, role permissions, lock and unlock controls, and security activity logging.

When to add OTP Pro

Consider OTP Pro if you need:

  • extra protection for high-risk admin changes
  • step-up verification before sensitive actions are applied

When to add SFS Vault

Consider SFS Vault if you need:

  • Encrypted-at-rest storage for files held in enclaves.
  • A single governed secure-root location with stricter storage boundaries.
  • Tokenised, time-limited file delivery controls.

When to add SFS Gateway

Consider SFS Gateway if you need:

  • Controlled sharing of secure enclave files with external recipients who are not EE members.
  • Time-bounded, revocable access links for approved sharing scenarios.

All companions use the same underlying policy model as SFS Access. You do not need to redesign your enclave structure when adding them.

If your priority is security incident response, start with SFS Access controls first (lockdown, membership control, and policy checks), then add OTP Pro or Vault where you need stronger protection for sensitive actions or sensitive data at rest.