Skip to content
Work and commercial: Coworking and flex space

Coworking and flex space: day guests on the portal, staff on EAP-TLS, a personal WiFi key per member

Each member company sits on its own VLAN or role over one set of access points. Its staff authenticate through its own directory, day-pass users and event guests come in on the portal, and every printer and screen gets a MAC-bound key. One authentication log spans all three networks.

  • 80,000+ venues in 90 countries
  • 1,000+ connectors
  • 99.9% RADIUS uptime SLA
  • A VLAN or role per member company
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the coworking and flex space network

Who connects, and where each one lands

A member company is a VLAN or role on shared access points, driven by the directory it already runs, so one set of radios carries many organisations and the operator keeps one log.

Who connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Day-pass users, visitors and meeting-room guestsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, with no key to hand out or collect
Member company staff and hot-desk members on their own laptopsOpenPurple app onboarding, certificate installed, no MDM (signed in with the company's own account)Onboarding lane, then the company's VLAN or role by directory groupEnds when the account is disabled in the company's directory
Community team and operations staffSecureEAP-TLS, certificate from your MDM over SCEPStaff VLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Member companies' printers, screens and room kitxPSKIndividual key, MAC-boundThe member company's VLAN or role, a key per device, so a private office sees only its ownRevoked when the device is swapped or the company leaves
Event guestsxPSKIndividual key, MAC-bound (valid for the event only)An event VLAN with its own bandwidth limitEnds when the event does
Door controllers, meeting-room panels, CCTV and sensorsxPSKIndividual key, MAC-boundA device VLAN per class, apart from every member companyRevoked when the device is replaced
Contractors and fit-out crewsxPSKIndividual key, MAC-bound (time-limited, no MDM)A VLAN and bandwidth limit per keyEnds on its end date

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Coworking and flex space: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Day passes, event visitors and member staff on their own laptops

The guest lane and the BYOD onboarding lane. A day-pass user needs a browser, and a member's laptop on a hot-desk style floor needs a certificate with no MDM enrolment.

  • A portal for day passes and meeting-room guests. SSO, Google, Apple, SMS or custom fields, with consent recorded for GDPR and CCPA. Adding the splash URL and RADIUS to a controller takes under 15 minutes.
  • Guests apart from members. Access points place portal guests on a guest-only VLAN with client isolation on, so a visitor's laptop never sees a member company's printer.
  • Member staff with no MDM. A member signs in once in the Purple app with their company's Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Illustration

Lifecycle

Key lifecycle: onboard a company, key its kit, end its contract

The unit is the member company, and the systems of record are your member list and the company's own directory.

Create the member company once

Its staff authenticate through its directory, and its printers and screens are keyed from the console, in bulk from a device list or through the Purple API, each bound to its MAC address.

Illustration

Place the company on a VLAN or role

RADIUS returns the company's VLAN, role or group policy and a bandwidth limit, depending on your vendor. Your access points enforce it, and a shared-service rule such as the lobby printer lives on your gateway.

Illustration

Operate from one log

Every accept and reject carries the company, the method and the reason, so "which company owns this device" is a query. The log streams to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End a device, a person or a company

Replace a printer and you revoke one key. Disable a leaver in their directory and the pass stops being accepted. A company that moves out has its keys revoked, with RADIUS CoA ending live sessions.

Illustration

One authentication log

One log across every location and every company

Portal sign-ins, staff certificates and device keys land in the same log, so isolation between members is something you query, not something you assert.

  • Which devices sit on which company's VLAN, and which keys are still live after a company has left.
  • Which accounts authenticated today, on which network and by which method, and why any were rejected.
  • Whether an event key stopped authenticating when the event ended.
  • How many day-pass and event guests came through the portal, by location and hour.
Illustration

Audit

What a member company's security team asks the operator for

Prospective members send a questionnaire before they sign. The VLAN or role map and the authentication log are the answer to its network section.

  • ISO 27001 and Cyber Essentials Plus

    Held by Purple, which answers the supplier section of a member company's security questionnaire.
  • Evidence of separation

    A VLAN or role per company and an authentication line per device: the pair a member's IT team asks for in due diligence.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

The figures a member's IT team will check

Scale, an uptime SLA in your contract and the certifications Purple holds.

80,000+
venues run on Purple, in 90 countries
500M
logins a year
99.9%
cloud RADIUS uptime SLA, in your contract
ISO 27001
and Cyber Essentials Plus, held by Purple

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your locations already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Does each member company need its own SSID?

No. One xPSK SSID carries every key, and RADIUS returns the company's VLAN or role at authentication. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why an SSID per company does not scale.

A member company runs Entra ID. Can its staff use it for the WiFi?

Yes. Entra ID, Okta and Google Workspace work over SAML and SCIM, group membership decides the VLAN or role, and Conditional Access is honoured at authentication.

How do day-pass users and event guests stay off member networks?

Portal guests land on a guest-only VLAN with client isolation on, and an event key carries its own VLAN and bandwidth limit. Your access points enforce both, and a bandwidth limit is a cap, not a guarantee.

What happens when a member company moves out?

Its keys are revoked and its staff stop authenticating once their accounts are disabled in the company's own directory. RADIUS CoA ends live sessions on access points that support it, and every other company's keys are untouched.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring one member company's worth of kit: a laptop, a printer, a screen and an event guest. We issue each a key or a certificate, place it on the company's VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.