Skip to content
xPSK use case

Contractors and visitors: a personal WiFi key that ends on its date, with nothing to install

Contractors keep access long after the job ends because nobody owns the end date. A personal WiFi key (xPSK, iPSK, PPSK) carries its end date and its scope from the moment it is issued, visitors take the portal, staff take EAP-TLS, and all three land on their own VLAN in one log.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • 99.9% RADIUS uptime SLA
Illustration
Book my design session

The problem

Contractor access is easy to grant and rarely taken back

The person who grants WiFi access is not the person who knows when the job ended, so access outlives the work by default.

  • The site password is shared with the contractor, then with their sub-contractor, and nobody can say who holds it today.
  • Revoking one contractor means changing the password, which drops every device that legitimately uses it.
  • Enrolling a contractor's laptop in MDM is not an option, so the choice is full trust or no access.
  • Agency and seasonal staff arrive in dozens, and each leaver is a manual ticket that waits for the end of the month.
  • When something goes wrong, the log shows a shared key and cannot name the person who used it.
Illustration

How it works

Issue with an end date and a scope, and let it end itself

The end date is part of the credential. Nobody has to remember to take access back.

Issue by purpose, with an end date

Create the key in the console, through the Purple API or from a branded self-service portal, with an end date and a scope such as one site, one unit or one VLAN. A visitor signs in on the portal at reception and gets a session and a key.

Illustration

Place in the narrowest VLAN that does the job

RADIUS returns a VLAN or role and a bandwidth limit for the key, your access points enforce it and your gateway decides what may cross. A fit-out contractor lands on one unit's VLAN and reaches nothing else.

Illustration

Know who was on site, and what they reached

Every connection names the key, the device, the VLAN and the reason in one log, so "who was on site and what could they reach" is a query and not a recollection.

Illustration

End on the date, or earlier

The key expires on its date without anyone acting. Revoking early is one action on one key, with RADIUS CoA ending the live session on access points that support it.

Illustration

Open, secure or xPSK

Which of the three networks, for which person on site

Which of the three networks, for which person on site
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Visitors at reception and the publicOpenCaptive portal sign-in, consent recordedA guest VLAN with client isolation onSession and consent recorded at sign-in
Returning visitors with a Passpoint or OpenRoaming profileSecurePasspoint or OpenRoaming profileA guest or contractor VLAN, with no portal on returnProfile installed once, valid wherever the venue runs it
Your own staff and the people who sponsor a visitSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled in the directory ends access
Contractors' laptops and test equipment, with no MDMxPSKIndividual key, MAC-bound (time-limited, from the self-service portal or API)The VLAN of the site or unit they work inEnds on the date set, with nothing to uninstall
Agency and seasonal staff, onboarded in bulkxPSKIndividual key, MAC-bound (one key each, imported from a list)A VLAN per employer or roleSwitched off in bulk when the contract or season ends

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

What it covers

What you can do with it

  • Time-limited keys with nothing to install

    No MDM enrolment, no agent and no profile to remove afterwards. The key is a WPA2-Personal passphrase to the contractor's device.
  • Scoped to a place

    A key lands on the VLAN of the site, unit or tenant it was issued for, so a lift engineer and a cleaner on the same estate do not share a network.
  • Agency staff in bulk

    Onboard a list of agency or seasonal staff in one import and switch the whole batch off when the contract or season ends.
  • Self-service issue

    A branded portal lets the site team issue keys without a ticket to IT, with the same end date and scope enforced.

Where it matters

The industries that run into this most

Proof

Many employers on one set of access points

Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys.

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

How does a contractor get on with no MDM?

They receive a time-limited key from the self-service portal or the Purple API and join like any WPA2-Personal network. Nothing is installed, so nothing has to be removed at the end.

Can a key be extended or cut short?

Yes. The end date is part of the key, so extending a job is an edit and ending one early is a revoke, with RADIUS CoA ending the live session on access points that support it.

How is a contractor kept out of everything else?

By placement and not by trust. RADIUS returns a VLAN or role for the key, your access points enforce it and your gateway decides what may cross, so a contractor key reaches only what its VLAN is allowed to.

Where do visitors, contractors and staff land?

Visitors on the open network through the portal, staff on the secure network with EAP-TLS or directory groups, and contractors without MDM on xPSK with a time-limited key. Returning visitors can roam on Passpoint.

What does the log say afterwards?

Each accept and reject with the key, the device, the VLAN, the method and the reason, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Book a demo: we issue and revoke a key on a live network

Bring the contractors and agencies who work on your sites. We issue each a time-limited key and revoke one live, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.