Back to Case Studies

How Marqeta Traded JIT-on-Paper for Runtime Access Enforcement

Marqeta's prior tool checked the just-in-time box on paper while persistent accounts and week-long roles stayed behind. Britive's runtime authorization and access enforcement now holds privileged accounts to Zero Standing Privileges across AWS, Snowflake, and Salesforce, without slowing the engineers who keep its payment platform running.

EXPLOREEXPLORE

100%Engineering Workforce

On one access control plane across cloud & SaaS

0Standing Privileges

Held by human identities across critical infrastructure with the privilege scoped to the duration of the task

40%Reduction in TCO

By eliminating legacy vaulting infrastructure and dedicated platform staffing

The problemThe problem

SolutionSolution

OutcomeOutcome

Just-in-time on paper, standing access in practice

On paper, Marqeta had just-in-time access. In practice, it had two pain points hiding under a checked box. The first: the JIT tool was entitlement-on-demand in disguise, with every engineer holding a persistent account and roles that lingered for up to a week, so the standing risk the tool was bought to remove was still there, masked rather than managed.

The second: the brittle provisioning chain behind that tool was taxing engineering velocity every day, breaking under peak load and turning routine access into multi-system troubleshooting. Years of rapid growth had layered point solutions over Marqeta's most sensitive environments, and both pains traced back to that fragmentation.

To an outside observer, the box for just-in-time (JIT) access was technically checked The engineering teams were using an access tool designed to limit standing risk. But a closer look at the mechanics showed the reality did not match the promise of true just-in-time access.

PAIN POINT 1: Just-in-time in name only

  • Entitlement-on-demand, not JIT — Every developer and engineer still held a persistent, standing account inside AWS. When they authenticated, they simply arrived without a role attached.
  • Roles that lingered — When a user requested access, the tool attached the required role, and then that role stayed attached, often for up to seven days. The underlying accounts never left the environment.
  • Risk masked, not removed — Because access was deemed temporary on paper, the tool was used a justification to bypass thorough access reviews. For critical financial infrastructure, that model was mismatched for the long game.

The friction was not confined to lingering access. It bled into daily engineering velocity. The prior tool relied on complex, multi-hop provisioning chain, and every step added a way for access to break.

PAIN POINT 2: The compounding operational cost

  • Brittle multi-hop provisioning — A checkout triggered an API call to the identity provider, which pushed the user ID into a push group, which then synced into AWS. Two hops, multiple points of failure.
  • Rate-limit bottlenecks — During peak deployment hours, simultaneous checkouts routinely hit identity provider rate limits. If the directory service had even a minor hiccup the entire access pipeline collapsed, locking engineers out of production.
  • Troubleshooting overhead — A single access ticket required engineers to audit across three systems instead of two, adding more than 30% to day-to-day troubleshooting complexity, by the team's estimate.

Read the complete Marqeta case study

The Solution: Runtime Privilege Enforcement

From Entitlement-on-Demand to True ZSP — Persistent developer accounts were removed from AWS. Access policy now exists independently of identity presence. An approved request grants a window of time, not active access. The role is provisioned natively at the moment work begins, and stripped away the moment the session closes. Nothing lingers.

A Unified Access Surface — Marqeta replaced AWS Identity Center with the Britive dashboard. The full human cloud engineering workforce moved to this single access surface, so engineers no longer navigate multiple consoles just to find the access they need.

Security Written as Code — To match modern cloud-native development practice, the entire deployment was anchored in Terraform. Access policies live in the codebase, version-controlled and subjected to the same peer-review standards as any production configuration change.

Built Mid-Deployment: PagerDuty-Aware Access — Mid-deployment, Marqeta surfaced a non-negotiable requirement: engineers on call in PagerDuty needed immediate elevated access for incident response without waiting on a manual approval workflow. That capability did not exist in Britive at the time. Rather than queue it for a multi-quarter roadmap, Britive's product and engineering teams built and delivered a native, PagerDuty-aware capability ahead of go-live, in a matter of weeks. It is now a standard part of the platform. When an engineer is on call, Britive verifies that status at runtime and grants access immediately, while maintaining a strict zero-standing posture for everyone else.

We were paying for just-in-time access but getting multi-system bottlenecks. If our access model was breaking under the weight of our daily engineering deployments, there was zero chance it could deliver the speed and scale Al adoption demands securely or otherwise.

[ Chetan Jha ]

Head of Identity & Vulnerability Security, Marqeta

Eliminating Standing Privileges at Scale

Attack Surface Reduction: Across AWS, Snowflake, and Salesforce, the engineering team operates under Zero Standing Privileges. The multi-day standing roles that once left a continuous footprint are gone, replaced by short-lived privilege scoped to active work.

Zero Rate-Limit Bottlenecks: By bypassing directory infrastructure for live provisioning, Marqeta eliminated API rate-limiting bottlenecks. Troubleshooting is deterministic, confined to two systems instead of a web of intermediaries

One Common Access & Policy Model: The human cloud engineering workforce operates from a single dashboard across AWS, Snowflake, and Salesforce, instead of navigating multiple tool-specific consoles.

Built in Weeks, Before Go-Live: PagerDuty-aware access did not exist in the platform when Marqeta named it a non-negotiable. Britive built and delivered it ahead of go-live: on-call status verified at runtime, immediate elevated access for incident response, zero standing posture for everyone else. New capability for this customer, now a standard part of the platform.

Evidence by Architecture: Because access is created at runtime and removed when the session closes, the audit trail stays current by design. Every session is built on dynamic checkouts, so granular audit records are generated automatically at runtime, giving compliance teams clean verification data directly alongside native cloud infrastructure logs.

The Math Everyone is Doing: When stolen credentials are the way in, the average breach runs 246 days from intrusion to containment (IBM Cost of a Data Breach Report 2025). At Margeta, the role is stripped the moment the session closes. There is no persistent account to compromise, and no eight-month window for one to be used.