"Where's that file?" is the question that kills adoption
Most enterprise products don't fail at document storage — storing a file is easy. They fail at retrieval: a user knows a document exists, remembers roughly what it's about, and still can't find it because it's not attached to the record they're looking at, or it's buried under a generic "Documents" tab with no filtering.
The moment users can't trust that "documents on this client" actually shows every document related to that client, they go back to email attachments and shared drives — and the feature is effectively dead even though it technically works.
What keeps documents findable at scale
Every file needs a mandatory parent
Uploading without attaching to a client, project or entity should not be possible in the primary upload flow. An orphaned file is a file nobody will ever find again.
Show documents where the context already is
A document tab directly on the client or project record gets used. A separate global document module, disconnected from the record it's about, gets ignored.
Categorize by document type, not just filename
"Contract," "Invoice," "Correspondence" as a required field at upload time turns a flat file list into something filterable — and filenames alone almost never carry that signal reliably.
Preview inline before download
Forcing a download to check if it's the right file adds friction to every single lookup. A quick inline preview for PDFs and images saves that round trip almost every time.
Version, don't silently overwrite
Re-uploading a file with the same name should create a new version with history, not quietly replace the old one. Losing a prior version silently is a trust-breaking bug, not a minor inconvenience.
Permission-scope at the folder level, enforce at the file level
Users expect document access to follow the same role rules as the record itself. Design the permission model once, alongside the record's own access rules, not as a separate system.
Storage is a solved problem; retrieval design is the actual work
S3 or equivalent object storage handles the "keep the bytes safe" part reliably and cheaply. The genuine design and engineering effort goes into the layer above it: enforced context, categorization, inline preview and permission scoping — the parts that determine whether a user finds the file in ten seconds or gives up and emails someone to ask.
Budget the project accordingly. A document feature that "just uploads to S3" is a fraction of the real work of a document feature people actually rely on.
The takeaway
Document management lives or dies on retrieval, not storage: mandatory context on every upload, surfaced right on the record it belongs to, categorized, previewable, versioned, and permission-scoped consistently with the record itself. Get retrieval right and people trust the system enough to stop emailing files as a backup plan.
Let's talk about your frontendRelated reading
Data · Trust
Change-Log Audit Trails: Designing for "Who Changed What, When"
Data · Tables
Designing Data Tables That Don't Overwhelm Users
UX · Content
Designing Empty States That Actually Help Users
See document management applied in production on the FarmGate case study.