Integration

Choosing where files live

Start with managed storage, connect storage you control, and move files without breaking links.

Applies to V1.2+ · Checked July 2026

Before you start

  • Workspace owner or admin access to change connections

Choosing where files live

Cygnetree gives every workspace a ready-to-use storage default. You can also connect storage your business controls. File links, project relationships, permissions, and history stay in Cygnetree even when the underlying provider changes.

Clients and vendors can preview explicitly shared PDF, plain-text, JPEG, PNG, GIF, and WebP files in a protected browser tab before downloading. Active formats such as HTML, JavaScript, and SVG remain download-only. A preview records Previewed for the originating workspace just as an explicit download records Downloaded; it never exposes whether a workspace member viewed material supplied by a client or vendor.

Start without configuring anything

Use Settings → File storage → Managed by Cygnetree if you want to start immediately. You do not need an AWS account, bucket, access key, or provider decision to test the rest of Cygnetree.

Storage is not a feature paywall. Your subscription includes a set amount of Cygnetree-managed space, and Settings → File storage always shows how much of it you are using and what happens when it fills.

What happens when the included space runs out

Nothing you already have is touched. Every file stays available to open, download, and share, and every contract, invoice, and message that references one keeps working. Only new uploads to Cygnetree-managed storage pause — and a client answering a file request you sent them can still upload into a reserve above the limit, so you are never the reason they get an error.

From there you can free up space, add an optional storage bolt-on, or connect storage you own and leave the limit behind entirely.

How managed storage is kept tidy

So the included space lasts, files in Cygnetree's own storage are cleaned up on a schedule. Replaced versions go after 90 days, and files you archived and left archived go after a year. Both are listed on your Files page, by name and date, at least 14 days beforehand, and stay recoverable for 30 days after they go. Uploads that never finished are cleared after a week.

Some files are never included, no matter how old:

  • anything attached to a contract, invoice, expense, message, task, form, or project timeline;
  • anything a client or vendor can see, and anything a client uploaded when you asked for it;
  • anything queued on a draft or scheduled message;
  • anything in storage you connected yourself. That is your space, and Cygnetree does not touch it.

Bring your own storage

Workspace owners and admins can connect an S3-compatible destination. This includes AWS S3 and services such as Cloudflare R2, Backblaze B2, and MinIO.

Use credentials restricted to the bucket and root prefix you enter. Cygnetree encrypts the credentials and never displays them again. Test connection writes and removes one small health object before the destination can become your default.

Google Drive is available after a workspace owner registers the workspace's Google OAuth application. Open Settings → Integrations, choose Google Workspace, and select Drive by itself or alongside Gmail, Calendar, and Meet. The wizard discloses each permission separately and combines the selected tools into one consent screen. Cygnetree creates or reuses a visible Cygnetree folder only when Drive is selected, encrypts the refresh token, and keeps provider tokens out of client and vendor browsers.

A Drive connection can be tested and used as a migration destination immediately. It cannot become the default for new uploads until the platform's provider-neutral malware scanner is enabled. Cygnetree shows that state rather than quietly making unscanned files downloadable.

Microsoft 365 is available after a workspace owner registers the workspace's Microsoft OAuth application. Open Settings → Integrations and select OneDrive and/or SharePoint, with or without Outlook, Calendar, and Teams. Selecting OneDrive creates or reuses a visible Cygnetree folder. Selecting SharePoint creates a pending storage profile without touching OneDrive; enter the full SharePoint site URL on the saved connection, load that site's document libraries, and choose where the dedicated folder belongs. Drive and SharePoint are workspace resources, so only a workspace owner or admin can add them; members can still connect personal mail, calendar, and meeting identities.

Microsoft refresh tokens are encrypted and automatically replaced when Microsoft rotates them. Provider access tokens and preauthenticated upload addresses never appear in permanent file links. As with Google Drive, Microsoft storage cannot become the default until malware scanning is ready.

Box is available after a workspace owner registers the workspace's Box OAuth application. Choose Connect Box to create or reuse a top-level Cygnetree folder. Box access is limited to file and folder read/write operations; Cygnetree does not request Box administration permissions. Because Box refresh tokens are single-use, Cygnetree serializes token renewal and stores each replacement before continuing.

Box uploads pass through an authenticated Cygnetree streaming relay so the Box access token never enters a workspace, client, or vendor browser. The same size, checksum, provider verification, and malware-scan gates still apply. Box uses the same logical links and migration model as every other provider.

Your workspace does not need to choose or operate a scanner. Cygnetree administrators configure one provider-neutral service for managed storage, Drive, Microsoft 365, Box, and S3-compatible connections that use external scanning. The service is enabled only after it correctly rejects a standard antivirus test file. If it becomes unavailable, pending files stay locked rather than silently bypassing the check.

Change the default safely

Choosing Use for new uploads changes only where new files go. Existing files stay readable from their recorded provider. This avoids an unexpected transfer, provider egress bill, or broken link.

If your connection is unhealthy, Cygnetree does not silently send new uploads there. The managed platform default remains available only while both its provider and required scanner are healthy and configured.

Choose a destination for one project

Workspace owners and admins can open a project and choose a different healthy, scan-ready tenant-owned destination under File destination. New workspace, client, and permitted vendor uploads for that project use the explicit destination. Choose Restore workspace default to resume inheriting the workspace destination, or managed storage when the workspace has no usable override.

An explicit project destination fails closed if it becomes unavailable. Cygnetree does not silently place that project's new files somewhere else. Existing files stay pinned to the provider recorded on each logical file, and a safe replacement stays with the current file's provider. Use a reviewed storage migration when you intend to move existing files or their version history.

Move existing files

Use Move existing files when you want the objects themselves to change providers.

  1. Create a dry-run plan.
  2. Review its file count and total size.
  3. Type MIGRATE to approve a live copy.
  4. Run bounded batches until complete.
  5. Resolve any item marked needs attention before revoking the old provider credentials.

Cygnetree copies and verifies each object before switching its logical file record, so project links and activity history do not change. Previous file versions move with the current version so a provider change never strands revision history. Cygnetree pauses a migration plan when a replacement upload is still being checked.

To replace a file without breaking its links, open Manage, choose a new file under Upload version, and select Replace safely. The current version remains downloadable while the new bytes are verified and scanned. Only a clean replacement becomes current. Earlier clean versions remain available under Previous versions; failed or malicious replacements never displace the working file.

Request files from clients

Open Files → Request files from a client, choose a project, and describe what you need. The project must have a primary client, and a storage default with malware scanning must be ready before you can publish the request.

The request appears in that client's private portal. Uploads automatically inherit the request, project, client visibility, current storage destination, file-count limit, and safety policy. The client can see when a file is still being checked, but neither side can download it until the scanner reports it clean.

Changing storage providers later does not change the request or its portal history. Use Message client from the request when you want to explain the request or follow up without copying a public upload link.

Share project files deliberately

Workspace uploads begin as Only my workspace. Open a file's Manage menu to change access to the project's client or to vendors who have file permission. A workspace-library file cannot be shared externally until it belongs to a project.

Client access follows the project's primary-client relationship. Vendor access follows each partner's project-specific See shared files permission; Upload files is a separate permission and automatically includes visibility. Removing the partner from the project or revoking file access takes effect on the next portal request because every download is authorized again instead of relying on a permanent public URL.

Files uploaded by a permitted vendor return to the same project as vendor-visible files and use that project's explicit destination when one exists, then the workspace or managed default. They still pass through verification and malware scanning before anyone can download them.

Reuse files across your work

A clean file can be attached to a project timeline, form, contract, or invoice without uploading a second copy. Open the record's attachment panel, choose a file from the workspace or matching project library, and add an optional note. These record attachments stay inside the workspace; share the underlying project file deliberately when a client or vendor should receive it.

The attachment points to the file's stable identity. Replacing the file with a clean newer version updates every attachment while preserving prior versions, and moving storage providers does not break the record link. Cygnetree rejects attaching a project-owned file to a different project. Removing an attachment removes only that record link; it does not delete the shared file.

Understand upload safety

Uploads use short-lived private forms with exact content-type and size limits. A successful upload is not immediately downloadable: Cygnetree verifies the stored object and waits for a malware scanner to report it clean.

Files with a malicious, failed, missing, or unknown scan result remain unavailable. Cygnetree does not offer an “open it anyway” shortcut.

Keep going

Did this guide get you unstuck?

If not, tell us — this opens a support conversation with the guide already attached, and a real person reads it. If the guide is wrong or missing something, we fix the guide.

Tell us what's missing