Coworking and flex space: day guests on the portal, staff on EAP-TLS, a personal WiFi key per member
Each member company sits on its own VLAN or role over one set of access points. Its staff authenticate through its own directory, day-pass users and event guests come in on the portal, and every printer and screen gets a MAC-bound key. One authentication log spans all three networks.
- 80,000+ venues in 90 countries
- 1,000+ connectors
- 99.9% RADIUS uptime SLA
- A VLAN or role per member company
Who is on the coworking and flex space network
Who connects, and where each one lands
A member company is a VLAN or role on shared access points, driven by the directory it already runs, so one set of radios carries many organizations and the operator keeps one log.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Day-pass users, visitors and meeting-room guests | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, with no key to hand out or collect |
| Member company staff and hot-desk members on their own laptops | Open | Purple app onboarding, certificate installed, no MDM (signed in with the company's own account) | Onboarding lane, then the company's VLAN or role by directory group | Ends when the account is disabled in the company's directory |
| Community team and operations staff | Secure | EAP-TLS, certificate from your MDM over SCEP | Staff VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Member companies' printers, screens and room kit | xPSK | Individual key, MAC-bound | The member company's VLAN or role, a key per device, so a private office sees only its own | Revoked when the device is swapped or the company leaves |
| Event guests | xPSK | Individual key, MAC-bound (valid for the event only) | An event VLAN with its own bandwidth limit | Ends when the event does |
| Door controllers, meeting-room panels, CCTV and sensors | xPSK | Individual key, MAC-bound | A device VLAN per class, apart from every member company | Revoked when the device is replaced |
| Contractors and fit-out crews | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and bandwidth limit per key | Ends on its end date |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Coworking and flex space: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Day passes, event visitors and member staff on their own laptops
The guest lane and the BYOD onboarding lane. A day-pass user needs a browser, and a member's laptop on a hot-desk style floor needs a certificate with no MDM enrollment.
- A portal for day passes and meeting-room guests. SSO, Google, Apple, SMS or custom fields, with consent recorded for GDPR and CCPA. Adding the splash URL and RADIUS to a controller takes under 15 minutes.
- Guests apart from members. Access points place portal guests on a guest-only VLAN with client isolation on, so a visitor's laptop never sees a member company's printer.
- Member staff with no MDM. A member signs in once in the Purple app with their company's Microsoft, Google or Okta account and a certificate-backed WiFi pass installs, on Windows, macOS, Linux, iOS and Android.
Community team and member directories: EAP-TLS and groups
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN or role for the group, so each company lands in its own lane.
- EAP-TLS for your own fleet. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP to the community team's laptops and phones. Setup is five to ten minutes, once.
- Each member company's directory drives its VLAN. A member company on Entra ID, Okta or Google Workspace uses it as the identity behind its own staff WiFi, over SAML and SCIM. Group membership decides the VLAN or role.
- Conditional Access honored. Entra ID Conditional Access and device posture are evaluated at authentication, so a non-compliant laptop does not join.
Printers, screens, room kit and event guests: a key each
Anything with no 802.1X supplicant, no screen or no certificate store gets its own key on one SSID. MAC binding stops a key becoming a second shared password.
- Printers, screens and meeting-room kit. Each device gets its own MAC-bound key, VLAN and bandwidth limit, issued in bulk from a device list or through the Purple API.
- Event guests for the event only. A key per event with its own VLAN and bandwidth limit, ended when the event ends, so event traffic never lands on a member company's network.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
- Building systems in their own lane. Door controllers, panels, CCTV and sensors on a device VLAN apart from every member company. Inter-VLAN rules live on your gateway.
- Private office isolation. A private office's laptops, printers and screens see each other and nobody else.
- Wall ports on the company network. Wall ports in a private office join the same company network, so a wired desk and a wireless one are on one network.
Lifecycle
Key lifecycle: onboard a company, key its kit, end its contract
The unit is the member company, and the systems of record are your member list and the company's own directory.
Create the member company once
Its staff authenticate through its directory, and its printers and screens are keyed from the console, in bulk from a device list or through the Purple API, each bound to its MAC address.
Place the company on a VLAN or role
RADIUS returns the company's VLAN, role or group policy and a bandwidth limit, depending on your vendor. Your access points enforce it, and a shared-service rule such as the lobby printer lives on your gateway.
Operate from one log
Every accept and reject carries the company, the method and the reason, so "which company owns this device" is a query. The log streams to Microsoft Sentinel, Splunk, Elastic or Datadog.
End a device, a person or a company
Replace a printer and you revoke one key. Disable a leaver in their directory and the pass stops being accepted. A company that moves out has its keys revoked, with RADIUS CoA ending live sessions.
One authentication log
One log across every location and every company
Portal sign-ins, staff certificates and device keys land in the same log, so isolation between members is something you query, not something you assert.
- Which devices sit on which company's VLAN, and which keys are still live after a company has left.
- Which accounts authenticated today, on which network and by which method, and why any were rejected.
- Whether an event key stopped authenticating when the event ended.
- How many day-pass and event guests came through the portal, by location and hour.
Audit
What a member company's security team asks the operator for
Prospective members send a questionnaire before they sign. The VLAN or role map and the authentication log are the answer to its network section.
ISO 27001 and Cyber Essentials Plus
Held by Purple, which answers the supplier section of a member company's security questionnaire.Evidence of separation
A VLAN or role per company and an authentication line per device: the pair a member's IT team asks for in due diligence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
The figures a member's IT team will check
Scale, an uptime SLA in your contract and the certifications Purple holds.
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- ISO 27001
- and Cyber Essentials Plus, held by Purple
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your locations already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Does each member company need its own SSID?
No. One xPSK SSID carries every key, and RADIUS returns the company's VLAN or role at authentication. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why an SSID per company does not scale.
A member company runs Entra ID. Can its staff use it for the WiFi?
Yes. Entra ID, Okta and Google Workspace work over SAML and SCIM, group membership decides the VLAN or role, and Conditional Access is honored at authentication.
How do day-pass users and event guests stay off member networks?
Portal guests land on a guest-only VLAN with client isolation on, and an event key carries its own VLAN and bandwidth limit. Your access points enforce both, and a bandwidth limit is a cap, not a guarantee.
What happens when a member company moves out?
Its keys are revoked and its staff stop authenticating once their accounts are disabled in the company's own directory. RADIUS CoA ends live sessions on access points that support it, and every other company's keys are untouched.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring one member company's worth of kit: a laptop, a printer, a screen and an event guest. We issue each a key or a certificate, place it on the company's VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.