Spreetail Success Story - Customers - Aserto

Spreetail manages user permissions and authorizes every service request with Aserto

20x cost reduction over building / maintaining an in-house system
Better security posture via policy change & decision log audit trail
Sidecar deployment provides big speed and availability gains

About Spreetail

With well over $1b in annual revenue, Spreetail is the largest end-to-end ecommerce partner in the US. It connects over 600 vendors with 18 online marketplaces, including Amazon, Walmart, eBay, Target, and many others. Spreetail buys, stocks, sells, ships, and supports its customers’ products anywhere online. With 8 fulfillment centers, Spreetail can reach 95% of US households with 2-day delivery, and 80% with next-day delivery.

Challenge

Over its 14 years of operation, Spreetail has built many internal systems, but the Vendor Portal is its first customer-visible piece of software. The portal gives vendors and partners a self-service experience for managing aspects of their product portfolio and provides insights into how products are performing and where opportunities exist to improve performance.

To get the initial product out the door, Spreetail built a homegrown system called “authz” that provides a solid authorization model, but didn’t address many use cases. For example, vendor managers, who support multiple vendors in a particular segment or geography, should be able to access information only for those vendors. A fine-grained authorization model that incorporated both user and resource context was necessary to achieve these goals.

Spreetail considered extending “authz” and going down a path of making authorization a core competency of its engineering organization, but its engineering leaders recognized that building this expertise wasn’t going to generate additional customer value or revenue - it was the “cost of doing business” without being a source of differentiation.

Solution

Spreetail uses Okta as its identity provider but didn’t want to manage fine-grained attributes and permissions in Okta, since this would require granting operational access to a system that should be locked down. Instead, Spreetail uses Okta as the “source of truth” for core identity data and syncs this data into the Aserto directory, which is the operational system for managing permissions for users.

Instead of creating static roles, Spreetail defines permissions and permission sets, which are dynamically assigned to users based on attributes. The system defines “smart groups”, which pre-seed some permissions based on user attributes such as "title". An additional mechanism called “dimensions” allows defining access to a subset of vendors based on properties such as country, region, and vendor type. This authorization model provides the flexibility in granularity that Spreetail was looking for.

Spreetail has built an authorization portal which allows admins to manage users, groups, permissions, and dimensions. These are stored in the Aserto directory, and changes are automatically pushed to the edge, where the Aserto authorizer is deployed. The authorizer is able to use these extended properties in Spreetail’s authorization policies.

Results

Spreetail now has a flexible fine-grained authorization system that can handle their sophisticated use cases. Authorization changes can no longer be made by editing rows in a database table - instead, they are made through a policy-as-code workflow, with each change being part of an audit trail.

Spreetail also finds the sidecar deployment model to produce very fast authorization decisions for their API requests, as well as insulating the performance and availability of the vendor portal from any potential Aserto availability or outage issues.

Spreetail went live with their Aserto-based authorization system in the summer of 2022, and the engineering team has been progressively migrating all of their internal services to use it.

Benefits