Skip to content
Industries

Work and commercial WiFi: a personal WiFi key for every tenant and device

The landlord owns the access points, each tenant owns its identity. Staff sit on EAP-TLS or directory groups, printers and building systems on keys, and visitors on the open network, with a VLAN or role per organisation.

  • 80% fewer IT helpdesk requests at McDonald's
  • JPMorgan runs staff WiFi on Purple across 5,000 branches
  • 80,000+ venues in 90 countries
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Work and commercial

Work and commercial: pick your estate

Many organisations, one building: each company, member or retailer on its own network, on radios and an uplink the landlord runs once.

  • Coworking and flex space

    A member company is a VLAN or role on shared access points, driven by the directory it already runs, so one set of radios carries many organisations and the operator keeps one log.
  • Multi-tenant office buildings

    The landlord owns the radios and the uplink and each tenant owns its identity: a VLAN or role per tenant on the landlord's access points, with building systems such as HVAC and access control in a lane of their own.
  • Corporate offices

    Certificates for every device that can hold one, a personal key for everything 802.1X cannot reach, and one directory driving joiners and leavers across all three networks.
  • Shopping malls

    Each retailer is its own merchant on the mall landlord's access points, so each gets its own VLAN and key set while shoppers stay on the portal and the centre team keeps one log across every tenant.
  • Retail chains

    One VLAN, key and role template pushed to 5 stores or 5,000: every device class isolated by type, seasonal keys that end with the season, and no per-SSID key ceiling.

Use cases

The problems that thread these estates

FAQ

Questions IT leads ask

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Who owns what in a multi-tenant building?

The landlord owns the radios and the uplink, and each tenant owns its identity. One platform returns a VLAN or role per tenant, and a tenant that runs Entra ID, Okta or Google Workspace uses it as the identity behind its own staff WiFi.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.