A Secure B2E (Business-to-Employee) Commerce Platform on Magento Open Source

Woolworths is one of Australia’s largest and most iconic retailers, employing hundreds of thousands of team members across the country. To reward and engage its workforce, the group operates the Woolworths Plus Club — a private, members-only employee benefits eCommerce platform offering exclusive products, vouchers, and gift cards to staff.

Built on Magento Open Source, this B2E (business-to-employee) commerce portal has unique requirements: strict access controls, secure handling of high-value digital products, deep CRM and gift card integrations, ongoing fraud prevention, and continuous performance optimisation — all serving a user base of more than 250,000 eligible members.

Acidgreen has been the trusted long-term partner of Woolworths on this platform for approximately 4 to 5 years, providing strategic Magento maintenance, security, integrations, and performance uplift to keep the experience secure, stable, and continuously improving.

Expertise

B2E eCommerce Strategy – Magento Open Source Maintenance & Optimisation – Magento Security Patching – Custom Magento Development – Salesforce CRM Integration – Gift Card & Voucher Commerce – Fraud Prevention & Risk Controls – Performance Engineering – Long-term Application Management

Technologies

Magento Open Source – Salesforce CRM – Blackhawk Network (Gift Cards) – Custom Authentication & Access Controls – Custom Fraud Prevention Tooling – Performance & Monitoring Stack
250k+
eligible employees with access to the members-only portal
4–5 yrs
of continuous Magento maintenance, security, and optimisation partnership
3
strategic integrations (Salesforce CRM, Blackhawk gift cards, custom access control)
0
major security incidents thanks to regular patching and proactive monitoring

How can a national retailer operate a secure, high-performing B2E commerce portal on Magento Open Source, serving 250,000+ employees with sensitive products like gift cards and vouchers — while keeping fraud, security, and engagement under control?

Project objectives
  1. Maintain and continuously evolve a secure Magento Open Source platform for employee benefits commerce
  2. Enforce strict access restriction so that only eligible members can browse and purchase
  3. Operate robust integrations with Salesforce CRM and Blackhawk gift cards
  4. Deploy fraud prevention controls, including a dedicated “void button” for high-risk transactions
  5. Ensure regular security patching, performance uplift, and long-term platform health

The Challenge

A Secure, Members-Only Commerce Platform at Enterprise Scale

Woolworths Plus Club is a complex eCommerce environment, with requirements that go well beyond a standard B2C store:

  1. A members-only platform restricted to verified Woolworths employees and eligible members — every visitor must be authenticated, every order traceable.
  2. A product and voucher catalogue that includes high-value digital goods (notably gift cards via Blackhawk), which are inherently attractive to fraudsters.
  3. Mission-critical integrations with Salesforce CRM for member data and Blackhawk Network for gift card fulfilment.
  4. A very large user base (250,000+ potential members) but historically low engagement, requiring ongoing UX, performance, and product improvements to convert eligibility into active usage.
  5. Strict expectations around security, compliance, and uptime consistent with the standards of a top-tier Australian retailer.

Our Approach

Long-Term Magento Partnership Built on Trust

Acidgreen’s role on Woolworths Plus Club is closer to a dedicated platform team than a one-off project — a model that has proven critical for a mission-sensitive B2E environment:

  1. Continuous platform management
    Day-to-day maintenance of the Magento Open Source environment, including monitoring, incident response, and proactive improvements.
  2. Security-first mindset
    Regular Magento security patching, vulnerability monitoring, and tightening of authentication and access control to keep the members-only experience secure.
  3. Integration ownership
    End-to-end ownership of the integrations with Salesforce CRM (member data, lifecycle, segmentation) and Blackhawk Network (digital gift cards), with monitoring of transaction flows.
  4. Fraud prevention engineering
    Design and operation of dedicated risk controls, including the “void button” allowing operators to instantly cancel suspicious or fraudulent transactions before fulfilment.
  5. Performance engineering
    Front-end and back-end optimisation to deliver faster page loads, smoother browsing, and a more enjoyable experience on a high-traffic platform.
  6. Strategic evolution
    Beyond pure maintenance, a continuous flow of UX, conversion, and engagement improvements designed to lift activation across the large eligible user base.

Key Features Implemented

A Secure, Stable, Long-Term Magento Partnership

Over approximately 4 to 5 years of continuous collaboration, Acidgreen has helped Woolworths run Woolworths Plus Club as a secure, stable, and continuously improving employee benefits eCommerce platform. The combination of disciplined Magento maintenance, proactive security, robust integrations, and focused fraud prevention has allowed Woolworths to operate a high-stakes B2E platform with confidence — protecting both the brand and its members. Just as importantly, the partnership has provided Woolworths with a trusted technical team that understands the platform inside-out, allowing the business to evolve the experience continuously rather than re-platforming or rebuilding from scratch.

Results

SECURITY

A continuously patched, hardened Magento Open Source platform with no major security incidents, protecting a sensitive members-only environment.

RELIABILITY

A stable, well-monitored B2E commerce experience supporting 250,000+ eligible users at enterprise scale.

FRAUD CONTROL

Bespoke fraud-prevention tooling — including the void button — protecting high-value gift card flows.

PARTNERSHIP

A long-term, trusted partnership of approximately 4 to 5 years, with continuous improvement in UX, performance, and platform health.

Why Magento Open Source for B2E and Employee Benefits Commerce?

Magento Open Source remains a strong choice for B2E (business-to-employee) commerce platforms and complex private storefronts because it combines:

  1. A fully customisable codebase, enabling unique access control, fraud, and integration requirements that go beyond standard SaaS limits.
  2. A mature catalogue, pricing and promotions engine, well suited to vouchers, gift cards, and exclusive employee offers.
  3. A large ecosystem of integrations with CRMs, gift card networks, ERP systems, and risk tools.
  4. A predictable cost model — particularly attractive for high-volume internal platforms where SaaS per-order costs can quickly escalate.
  5. A long, stable lifecycle, ideal for platforms that benefit from continuous evolution over many years rather than constant re-platforming.

Frequently Asked Questions

Ready to Build or Modernise Your B2E Commerce Platform?

If you operate a private, members-only commerce platform — employee benefits, loyalty club, internal marketplace, or partner portal — Acidgreen can help you design, secure, integrate, and continuously evolve it on Magento or another leading eCommerce platform.
Let’s talk

On the same topic

How to choose the right Magento and Adobe Commerce partners for your project?

Choosing the right Magento Partner in Australia is critical to your 2026 growth strategy. In this article, we outline the key criteria to select the right Adobe Commerce experts, from technical expertise to scalability and long-term performance.

Read news
How do you build a product data flow in Pimcore?

Struggling to structure and manage your product data efficiently? Building a solid data flow in Pimcore is key to ensuring consistency, automation, and scalability. In this article, we walk you through the essential steps to design a streamlined product data workflow that powers performance across all channels.

Read news