Featured
Fintech
Mercari, Japan's largest consumer-to-consumer marketplace, secures production systems with Opal to keep customer financial data secure.
Company: Founded in 2013, Mercari is Japan’s largest “C2C” (consumer-to-consumer) marketplace. The company has 2,300 employees, with 14.2B of annual revenue.
Challenge: Just-in-time access systems were built in-house, but were failing to keep up with changing developer and DevOps tools.
Solution: Opal maintains over 50 integrations, and automates on-call and break-glass access for Mercari, ensuring the team can focus on business problems, rather than building support for new development tools.
Operating Environment
Identity provider(s): Okta, Google Workspace
Core systems: GCP, GKE, GitHub
Workforce: 2,300 employees
Compliance/regulatory needs: Japan’s Act on the Protection of Personal Information (APPI), PCI-DSS, other industry specific Japanese regulations
Challenge
After being impacted by a supply chain security incident in 2021, Mercari implemented “Carrier,” a system for “Zero Touch Production” as a preventative measure to reduce the potential blast radius of similar incidents in the future.
Informed by Google’s SRE practices, they worked to implement on-call and “break glass” access to production instances. Today, Mercari is migrating from their in-house system to Opal so they don’t have to maintain a whole host of integrations with third-party services.
Mercari’s engineering teams are typically small and operate fairly autonomously, so access requests and approvals are best delegated to teams themselves.
Goals
Replace Carrier, the in-house access tool, with a more flexible platform
Enable faster access to production systems for on-call SREs without creating long-standing privilege
Eliminate the need to support various third-party services that Opal already supports
Opal Solution
Infrastructure-as-code via Terraform
Track GCP projects and their associated GKE instances
Just-in-Time and ”break glass” access for SREs on call
In 2021, Mercari experienced a security incident as a result of a supply chain attack. The aftermath of this led to various initiatives to improve their overall security posture. One of the risks highlighted was the potential impact of the exposure of long-lived credentials. To tackle this the Mercari Platform team worked on the development of an internal tool called Carrier, used to provide just-in-time role bindings. The goal was to achieve “Zero Touch Production,” removing, as much as possible, any need to maintain permanent access to systems.
“Opal enabled Mercari to migrate away from Carrier and sustain the same ‘Zero Touch Production’ mindset without the need for internal development and maintenance. Opal also allowed Mercari to expand just-in-time access to more developer tools and productivity applications.
It’s a huge relief to unload a lot of ‘keep the lights on’ maintenance work while improving our security posture in line with the broader business goal of keeping customer data safe.”
— Allan Wirth, Manager of Platform and AI Security, Mercari
Strategic Impact
With tedious “keep the lights on” work reduced, engineers can now focus more on business problems, all while still maintaining strong just-in-time access capabilities for our environment and high level of security in the solution to provide this.
“As agentic AI progresses further and there is more demand from the business to grant significant autonomy to agents, agents will need to be more and more treated as identities.
It will become important to visualize the data and functions agents handle and to be able to deploy circuit breakers, as well as enforce least agency, identify misalignment and to be able to isolate and handle rogue agents. We’re planning to look at the potential to extend the identity security paradigms we’ve built out in Opal for humans to LLM agents as needs arise here.”
Jason Fernandes
VP of Security & Privacy
