Warehouses and logistics: drivers on the portal, staff on EAP-TLS, a personal WiFi key per scanner
Scanners, robots and vehicle terminals join with a MAC-bound key on an operations VLAN, apart from staff phones. Permanent staff sit on EAP-TLS, agency staff are onboarded in bulk and switched off when the season ends, and visitors use the portal.
- 80,000+ venues in 90 countries
- 99.999% uptime
- 99.9% RADIUS uptime SLA
Who is on the warehouses and logistics network
Who and what connects to a depot, and where each one lands
A certificate has an expiry, and a scanner that sat in its cradle all off-season meets it on the first shift of peak, so scanners, robots and vehicle terminals get a MAC-bound key with no certificate to renew, and agency staff arrive in bulk and end on a date.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Permanent staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visiting drivers, customers and auditors at reception | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, session ends on timeout |
| Permanent warehouse, transport and office staff | Secure | EAP-TLS, certificate from your MDM over SCEP (managed laptops and phones) | VLAN by directory group, apart from the operations VLAN | Account disabled in the directory ends access |
| Agency and peak-season staff | xPSK | Individual key, MAC-bound (from a roster import, a personal phone, no MDM) | A seasonal-staff VLAN and a bandwidth limit per key | Switched off on the season's end date |
| Handheld scanners | xPSK | Individual key, MAC-bound | An operations VLAN, apart from staff phones | One key per scanner, revoked when it is retired |
| Mobile robots | xPSK | Individual key, MAC-bound | A robot VLAN with its own bandwidth limit | One key per robot, revoked alone |
| Vehicle terminals on forklifts and yard vehicles | xPSK | Individual key, MAC-bound | The operations VLAN | No expiry to chase while it sits in its cradle |
| Equipment maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN, crossings set at your gateway | Ends on the visit's end date |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Warehouses and logistics: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and staff phones: portal and onboarding lane
The guest lane and the BYOD onboarding lane, on VLANs that share nothing with the operations VLAN.
- Drivers and auditors at reception. A captive portal records consent and puts the session on a guest VLAN with client isolation on. A visiting driver's phone never sits on the segment a scanner does.
- Permanent staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
- A new depot in minutes. Add the splash URL and RADIUS to the depot's controller in under 15 minutes, on the access points already installed.
Office, supervisors and operations managers: EAP-TLS and groups
One WPA-Enterprise SSID across every depot. Cloud RADIUS checks the directory once and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for every depot.
- One directory, many depots. Entra ID, Okta or Google Workspace groups decide the VLAN at every site. Disable a leaver once and no depot authenticates them.
- One policy, however many access point brands. A group on the secure network lands on the same VLAN or role at every depot, on whichever vendor's access points that depot runs.
Scanners, robots and agency staff: a key each, a VLAN each
Everything that cannot hold a certificate you want to renew, plus the temporary workforce, on one xPSK SSID with a key and a policy per device or person.
- Scanners and vehicle terminals, no certificate to renew. A key has an end date only if you set one, so a terminal that comes back from storage on the first day of peak joins as it did last year.
- Robots on a VLAN of their own. A bandwidth limit per key stops one fleet's firmware push crowding the scanners that are picking against the clock.
- Agency staff in bulk, off on a date. Import the agency's roster and each person gets a key carrying the season's end date. When the date passes, RADIUS rejects the key and nobody collects a handset.
- Operational devices apart from staff phones. Scanners, robots and terminals sit on the operations VLAN and phones on staff VLANs, so a compromised phone shares no broadcast domain with a robot controller.
Lifecycle
Key lifecycle: deploy, place, operate, retire
The same four moves cover a scanner and a seasonal picker, tied to the records a depot already keeps: the device register, the agency's roster and the directory.
Issue in bulk, from the device register and the roster
Import the device list and the agency's roster, or issue from the console or the Purple API. Each key is bound to the device's MAC address, and each person's key carries the season's end date.
Place on the operations VLAN or the seasonal VLAN
RADIUS returns the VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and what the warehouse management system may reach lives on your gateway.
Operate from one log across every depot
Every accept and reject carries the device or person, the key, the VLAN and the reason, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Retire one scanner, or end a whole season
Retire a scanner and you revoke one key. When the season's date passes, every agency key stops authenticating, and RADIUS CoA ends a live session on access points that support it.
One authentication log
One authentication log for the fleet and the workforce
Scanners, robots, permanent staff and the seasonal intake land in the same log, so "which devices are on the floor and who is still switched on" is a query across every depot.
- Which scanners, robots and terminals authenticated today, by depot and VLAN.
- Which agency keys are live, and which ended on the season's date.
- Which devices were rejected, with the reason: revoked, unknown or off its bound MAC.
- Whether a retired scanner's key still authenticates anywhere.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Built for estates that never close
80,000+ venues in 90 countries run on Purple, on a platform that holds 99.999% uptime.
- 80,000+
- venues run on Purple, in 90 countries
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in our warehouses?
No. Purple Access is a cloud overlay on the access points your depots already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Why not certificates on every scanner?
Certificates stay the default for what can hold one and be managed: office laptops and managed phones on EAP-TLS. Rugged handhelds, robots and vehicle terminals carry a certificate lifecycle you would run across thousands of units that sit unused for months. xPSK gives them a key instead.
Do scanners keep their key as they roam between access points?
Yes. The key authenticates against RADIUS on the SSID, not on one access point, so a device keeps its key and its VLAN as it moves across your estate. Fast-roaming behaviour is a setting on your controller.
What happens when the season ends?
Each agency key carries the end date it was issued with. After it, RADIUS rejects the key, and a CoA ends a live session on access points that support it. Nobody chases handsets.
Does MAC binding work on rugged devices?
It is strongest on fixed-MAC devices, which scanners, robots and vehicle terminals are. The key is bound to the device's address, so a copied key does not work on another handset.
Can scanners still reach the warehouse management system?
Yes, by policy at your gateway or firewall. Purple returns the VLAN or role at authentication, and your gateway decides what the operations VLAN may reach, and what staff phones may not.
Does a VLAN per fleet mean an SSID per fleet?
No. One xPSK SSID carries every key and RADIUS returns the VLAN, so a new fleet adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime, which matters on a floor with hundreds of radios.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring a shift's worth of kit: a scanner, a robot, a vehicle terminal and an agency worker's phone. We issue each a key, place it on its VLAN and end one live.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.