Lucid Software Logo

From Bottleneck to Momentum: How Lucid Accelerated Engineering with Infisical

A new approach shifted sensitive access from a bottleneck to faster, team-owned work.

Lucid Software·North America·1,000+ employees
Infisical checked a lot of boxes, but what impressed us most was that they were responding to bug reports and implementing feature requests during the pre-sales cycle. Those empty checkboxes filled in rapidlyRocky Olsen, Principal SRE Software Engineer
About Lucid
Lucid Software is the leader in visual collaboration and work acceleration, helping teams see and build the future by turning ideas into reality. Its products include the Lucid Visual Collaboration Suite (Lucidchart and Lucidspark) and airfocus. 
The Lucid Visual Collaboration Suite, combined with powerful accelerators for business agility, cloud, and process transformation, empowers organizations to streamline work, foster alignment, and drive business transformation at scale. airfocus, an AI-powered product management and roadmapping platform, extends these capabilities by helping teams prioritize work, define product strategy, and align execution with business goals. 
The most widely used work acceleration platform among Fortune 500 companies, Lucid’s solutions are trusted by more than 100 million users worldwide, including Google, GE, and NBC Universal. Lucid partners with leaders such as Google, Atlassian, and Microsoft, and has received numerous awards for its products, growth, and workplace culture. 
Key Results
  • Replaced an internal secrets management tool, freeing engineering resources for core business work
  • Reduced manual secret operations through approval workflows and automation
  • Improved security posture with native authentication methods and granular access controls
The Challenge: Secrets Management Funneled Through One Small Team
Lucid’s original secrets setup worked early on, but it could not keep up with the company’s scale. Sensitive access changes were managed by a small, trusted group, which created delays and constant pressure.
Rocky Olsen, Principal SRE Software Engineer at Lucid, described the challenge they were facing: “When I started, it relied on a core group of four of us. We eventually expanded to eight people managing and updating secrets for the entire company. It didn’t scale, and it created a lot of stress and constant interruptions for senior engineers.”
What this meant day to day:
  • Teams had to wait for a small group to move work forward. 
  • Permissioning and structure were too basic for a large organization.
  • The burden and risk of “keeping secrets in shape” kept growing.
Security and compliance were non-negotiable. Lucid required a platform that supported self-hosting to satisfy FedRAMP constraints, which significantly limited their options. Simultaneously, external pressures accelerated the project: a sudden pivot in pricing and enterprise direction from their incumbent vendor meant Lucid needed to select a new solution quickly to avoid project delays.
The Solution: Self-Hosted, IAM-ready, Built for Control
Lucid needed a secrets management platform that fit strict security constraints without creating more work for engineers. Their non-negotiables for the platform they chose were clear: 
  • Designed to support FedRAMP compliance
  • Self-hosted deployment 
  • AWS IAM integration
  • Granular permissions and folder structure
Lucid didn't start with a sales pitch; they began by stress-testing Infisical’s open-source product. While the software met their technical requirements, it was the Infisical team’s agility that stood out. As Rocky Olsen recalls, "Infisical checked a lot of boxes, but what impressed us most was that they were responding to bug reports and implementing feature requests during the pre-sales cycle. Those empty checkboxes filled in rapidly".
After choosing Infisical, Lucid moved to a ‘hub-and-spoke’ model: Infisical manages the secrets, while automated syncs push them out to AWS services for runtime execution. This shift did more than just centralize management; it gave Lucid the perfect opportunity to reset. Instead of a ‘lift and shift’ of their old environment, they used the migration to standardize naming and build a much cleaner, more scalable secret structure.
Lucid also prioritized reducing day-to-day toil and improving resilience. Rocky called out credential rotation: “One of the big things for us is credential rotation. We were excited about dynamic credentials with Infisical and the ability to stop manually rotating secrets and dealing with the drama that comes with it.”
And on outages and backup access paths: “If AWS is down, Akamai is down, or something happened where we couldn’t get into 1Password, we can sleep peacefully at night, with our Lucid-branded stuffed corgis, knowing that we have access to those core secrets that live in Infisical.”
Infisical delivered:
  • Self-hosted deployment to meet security and FedRAMP constraints
  • AWS IAM integration for existing role infrastructure
  • Multi-environment secrets lifecycle management to reduce friction across environments
  • Multi-region support and cross-region syncing for low-latency access, including GovCloud
  • A path to reduce operational toil with dynamic credentials, automated rotation, and resilience via OnePassword sync
The Results: Less Waiting, Less Stress, More Momentum
Lucid’s shift to Infisical was driven by a simple goal: to take pressure off the small group that had become the default owner of sensitive access and to give teams a cleaner, faster path to the secrets they needed without constant back-and-forth. 
The rollout of Infisical focused on reducing the high-friction work that used to trigger interruptions and tedious manual tasks, especially around access controls and credential maintenance.
Rocky also pointed to the day-to-day experience and the working relationship as meaningful outcomes for them. He said, “Infisical has been awesome. It’s been a great relationship, and it’s felt like a real partnership.”
He also called out that “Infisical’s developer forward design around secret promotion between environments meant we didn’t need to build out complex workflows for syncing secrets between namespaces or mount paths,” which reflected the operational simplicity they were aiming for.
Key outcomes:
  • Reduced the secrets bottleneck through self-service ownership
    • Granular permissions enabled team ownership and reduced reliance on a small core team.
  • Cut manual work and fewer high-risk chores
    • Automated credential rotation and dynamic credentials reduced rotation overhead.
    • Teams are allowed to self service secrets within their perview
    •  12-20 hours saved per month
  • Improved resilience during incidents and outages
    • 1Password sync provided a backup access path when other systems were down.
  • Reduced admin toil in database access workflows
    • MySQL integration supported automated administrator account provisioning, reducing manual provisioning.
  • Supported large-scale, multi-region production deployments
    • Deployed across 8 regions including Govcloud
    • Supporting dozens of ECS Fargate and EC2 autoscaling groups in those regions
Lucid’s experience shows what’s possible when sensitive access stops being a bottleneck and becomes a system teams can rely on, which is exactly what Infisical is built to deliver.
Infisical: Make Secrets Management a System, Not a Scramble
When a small group has to manage sensitive access for everyone, speed suffers and stress builds. Infisical helps large engineering orgs shift that work into a standard system with clear ownership, so teams can move faster and stay confident access is controlled and consistent.
Want to see how it would work in your environment? Get a demo of Infisical.
Starting with Infisical is simple, fast, and free.