How Fireblocks keeps access requests under two minutes across a regulated, always-on business

Custody infrastructure runs around the clock, and so do its access requests. Fireblocks used Harmony to make least-privilege access self-service without loosening a single control.

median time to provision access
<2 min
of access requests handled without a human
94%
faster evidence collection at audit time
3x
standing privileges added
0

At a glance

Industry
Digital asset infrastructure and custody
Headquarters
New York, with engineering across three continents
Company size
Roughly 900 employees
IT and security team
Combined platform team of eleven
Coverage need
24/7 - trading desks do not stop for weekends
Harmony agents in use
Access management, ITSM triage, and audit evidence

Illustrative mockup. This story is sample content created to design and review the customer-story layout. The company is real; the metrics, quotes and people below are invented and must not be published or cited.

The challenge: least privilege that people actually wait for

Fireblocks secures the movement of digital assets for banks, exchanges and fintechs, which means its internal controls are audited constantly. Every production system sits behind a just-in-time access request, and every request needs an approver who understands the blast radius of saying yes.

That model held up well on paper and poorly at 2am. Requests queued behind whoever happened to be awake, and engineers responding to a live incident sometimes waited longer for a permission than for the fix itself. The platform team could not simply widen access, because standing privileges were the exact thing the control existed to prevent.

The control was right. The queue in front of it was the problem.

A. MercerDirector of Platform Security, Fireblocks (illustrative)

What changed: policy became something a system could read

Harmony now takes the request in Slack, resolves who the requester is, what they are asking for and which policy governs it, then either grants the scoped, time-boxed access outright or routes it to the one approver who genuinely needs to weigh in. Approvals that used to be judgement calls at 2am are now judgement calls made once, in policy, during business hours.

Because every grant is issued with an expiry, the number of standing privileges did not move. Access is broader in the moments it is needed and narrower the rest of the time.

We stopped trading security for speed. It turned out we were only ever trading it for a queue.

A. MercerDirector of Platform Security, Fireblocks (illustrative)

The result: audits stopped being a project

The side effect the team did not plan for was evidence. Every request, decision, policy citation and expiry is recorded as it happens, so the quarterly scramble to reconstruct who had access to what became a query. The platform team estimates it reclaimed several weeks a year that used to go to audit preparation.