Contractors and visitors: a personal WiFi key that ends on its date, with nothing to install
Contractors keep access long after the job ends because nobody owns the end date. A personal WiFi key (xPSK, iPSK, PPSK) carries its end date and its scope from the moment it is issued, visitors take the portal, staff take EAP-TLS, and all three land on their own VLAN in one log.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 99.9% RADIUS uptime SLA
The problem
Contractor access is easy to grant and rarely taken back
The person who grants WiFi access is not the person who knows when the job ended, so access outlives the work by default.
- The site password is shared with the contractor, then with their sub-contractor, and nobody can say who holds it today.
- Revoking one contractor means changing the password, which drops every device that legitimately uses it.
- Enrolling a contractor's laptop in MDM is not an option, so the choice is full trust or no access.
- Agency and seasonal staff arrive in dozens, and each leaver is a manual ticket that waits for the end of the month.
- When something goes wrong, the log shows a shared key and cannot name the person who used it.
How it works
Issue with an end date and a scope, and let it end itself
The end date is part of the credential. Nobody has to remember to take access back.
Issue by purpose, with an end date
Create the key in the console, through the Purple API or from a branded self-service portal, with an end date and a scope such as one site, one unit or one VLAN. A visitor signs in on the portal at reception and gets a session and a key.
Place in the narrowest VLAN that does the job
RADIUS returns a VLAN or role and a bandwidth limit for the key, your access points enforce it and your gateway decides what may cross. A fit-out contractor lands on one unit's VLAN and reaches nothing else.
Know who was on site, and what they reached
Every connection names the key, the device, the VLAN and the reason in one log, so "who was on site and what could they reach" is a query and not a recollection.
End on the date, or earlier
The key expires on its date without anyone acting. Revoking early is one action on one key, with RADIUS CoA ending the live session on access points that support it.
Open, secure or xPSK
Which of the three networks, for which person on site
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visitors at reception and the public | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| Returning visitors with a Passpoint or OpenRoaming profile | Secure | Passpoint or OpenRoaming profile | A guest or contractor VLAN, with no portal on return | Profile installed once, valid wherever the venue runs it |
| Your own staff and the people who sponsor a visit | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled in the directory ends access |
| Contractors' laptops and test equipment, with no MDM | xPSK | Individual key, MAC-bound (time-limited, from the self-service portal or API) | The VLAN of the site or unit they work in | Ends on the date set, with nothing to uninstall |
| Agency and seasonal staff, onboarded in bulk | xPSK | Individual key, MAC-bound (one key each, imported from a list) | A VLAN per employer or role | Switched off in bulk when the contract or season ends |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
Time-limited keys with nothing to install
No MDM enrolment, no agent and no profile to remove afterwards. The key is a WPA2-Personal passphrase to the contractor's device.Scoped to a place
A key lands on the VLAN of the site, unit or tenant it was issued for, so a lift engineer and a cleaner on the same estate do not share a network.Agency staff in bulk
Onboard a list of agency or seasonal staff in one import and switch the whole batch off when the contract or season ends.Self-service issue
A branded portal lets the site team issue keys without a ticket to IT, with the same end date and scope enforced.
Where it matters
The industries that run into this most
Corporate offices
Contractors on time-limited keys with nothing to install, while joiners and leavers follow the directory.Airports
Seasonal and contractor staff onboarded in bulk and switched off at season end, each organisation in its own VLAN.Shopping malls
Fit-out contractors given one unit's VLAN for the length of the fit-out, and nothing else.Care homes
Agency staff get a key that ends when their booking ends, on a VLAN apart from care systems.Smart buildings and IoT
Lift, HVAC and EV charging contractors on their own keys, apart from every tenant.Multi-tenant office buildings
Visitors get a key when they sign in at reception, and building systems stay in their own lane.
Proof
Many employers on one set of access points
Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
How does a contractor get on with no MDM?
They receive a time-limited key from the self-service portal or the Purple API and join like any WPA2-Personal network. Nothing is installed, so nothing has to be removed at the end.
Can a key be extended or cut short?
Yes. The end date is part of the key, so extending a job is an edit and ending one early is a revoke, with RADIUS CoA ending the live session on access points that support it.
How is a contractor kept out of everything else?
By placement and not by trust. RADIUS returns a VLAN or role for the key, your access points enforce it and your gateway decides what may cross, so a contractor key reaches only what its VLAN is allowed to.
Where do visitors, contractors and staff land?
Visitors on the open network through the portal, staff on the secure network with EAP-TLS or directory groups, and contractors without MDM on xPSK with a time-limited key. Returning visitors can roam on Passpoint.
What does the log say afterwards?
Each accept and reject with the key, the device, the VLAN, the method and the reason, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Book a demo: we issue and revoke a key on a live network
Bring the contractors and agencies who work on your sites. We issue each a time-limited key and revoke one live, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.