Senior living: families on the portal, staff on EAP-TLS, nurse call on a personal WiFi key per device
Alarm devices get MAC-bound keys on a care-systems VLAN residents never reach. Care staff authenticate with EAP-TLS or directory groups, families sign in on the portal, and one authentication log covers assisted living, independent living and every community you run.
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
- ISO 27001 and Cyber Essentials Plus
- Nurse call on its own VLAN
Who is on the senior living network
Who and what connects, and where each one lands
Nurse call and fall detection on a key and VLAN of their own, never mixed with residents' streaming.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visiting family and friends | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on, apart from resident and care lanes | Consent recorded at sign-in, and no account to clean up afterwards |
| Agency and bank staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Care staff, managers and maintenance | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Visiting clinicians who return every week | Secure | Passpoint or OpenRoaming profile | Guest-class VLAN, with no portal on return | Profile installed once, valid at every community that runs it |
| Residents' tablets, TVs and phones | xPSK | Individual key, MAC-bound (one key per device) | A resident VLAN or role, client isolation on, a bandwidth limit per key | Key ends when the device is retired or the resident moves out |
| Nurse call, fall detection and wander alarm devices | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A care-systems VLAN per device class, unreachable from residents and guests | Revoked alone when a unit is replaced |
| Voice assistants in resident rooms | xPSK | Individual key, MAC-bound | A resident-device VLAN, isolated, on the same SSID as every other key | One key per assistant, rotated or revoked on its own |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Senior living: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Families and staff phones: portal and onboarding lane
The guest lane and the BYOD onboarding lane. Visitors never touch a resident's network or an alarm VLAN, and staff personal phones join without enrolling in device management.
- A guest VLAN apart from care and residents. Visiting family sign in on the captive portal, with consent recorded for GDPR and CCPA and client isolation on, so a visitor's laptop cannot see a resident's tablet.
- Staff personal phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android. The directory account decides the VLAN.
Care staff: EAP-TLS and directory groups
One WPA-Enterprise SSID. Cloud RADIUS checks the directory and returns the VLAN for the group, so care, management and maintenance each land in their own lane across every community.
- EAP-TLS for the managed estate. Care-planning tablets, nurse-station PCs and managers' phones get a certificate from your MDM over SCEP: Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every community stops authenticating them, with RADIUS CoA ending the live session.
- Passpoint for visiting clinicians. A GP or physiotherapist who visits weekly installs a profile once and rejoins on their own, with OpenRoaming free through the Connect license.
Alarms, assistants and residents' devices: a key each, on its own VLAN
Anything with no 802.1X supplicant, no screen or no certificate store gets its own key on one SSID. MAC binding stops a key becoming a second shared password, and the safety lane stays shut to everything else.
- Nurse call, fall detection and wander alarms. Each unit on its own MAC-bound key and a care-systems VLAN, so a resident streaming a film shares an access point with the alarm system and nothing else.
- Voice assistants on per-device keys. A key per assistant on the existing xPSK SSID, not a separate network. 8 to 10 SSIDs use 15 to 25% of channel airtime, and a room-by-room SSID would spend that airtime again.
- Residents' own tablets and TVs. A key per device, on a resident VLAN with client isolation on. To the device, the key is an ordinary WPA2-Personal passphrase, so a care assistant can set one up with no portal and no account.
Lifecycle
Key lifecycle: install, place, operate, retire
The same four moves serve an alarm pull-cord, a resident's tablet and an agency worker, tied to the records you already keep: your device register, your schedule and your directory.
Issue at installation or admission
Key an alarm unit when the installer commissions it, and a resident's devices when they move in: from the console, in bulk from your device list, or through the Purple API. Each key is bound to the device's MAC address.
Place on the lane the device class needs
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and rules between lanes, such as the alarm gateway reaching its monitoring service, live on your gateway.
Operate from one log
Every accept and reject carries its reason, by resident device, member of staff and alarm unit, across every community, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
End one key, or one leaver
Replace a pull-cord unit and you revoke its key alone. When a resident moves out their keys end and nobody else is disconnected. Disable a leaver and the certificate stops being accepted.
One authentication log
One authentication log across every community
Alarm units, residents' devices, staff certificates and visitor sessions land in the same log, so "what is this device, and whose is it" is a query and not a walk round the building.
- Which alarm devices are on the network at each community, on which VLAN, and when each last authenticated.
- Which staff accounts authenticated today, by which method, and which were rejected and why.
- Whether a device on a resident lane is one you issued a key to.
- Whether a leaver's session ended when the account was disabled.
- How many visitors used the portal this week, kept apart from care systems.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Care estates run on the same platform
Purple Access runs on 80,000+ venues in 90 countries, and St George's Healthcare NHS Trust saves £12k a year on patient iPads for family calls.
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Can nurse call and fall detection share access points with residents' tablets?
Yes, and stay apart. Each alarm unit gets a key bound to its MAC and RADIUS returns a care-systems VLAN, while residents' devices sit on keys of their own. Your access points and gateway keep the lanes separate, and the log shows which key each device used.
Do voice assistants in every room mean an SSID per room?
No. A voice assistant has no supplicant and no browser, so it joins on an xPSK key like any other device, on the one SSID. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why per-room or per-device SSIDs are the wrong design.
Do we need new access points in our communities?
No. Purple Access is a cloud overlay on the access points your communities already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How are residents kept apart from one another and from care systems?
Client isolation is on by default, and each class of device lands on its own VLAN or role returned by RADIUS. Access points and your gateway enforce it. Anything that must cross lanes, such as an alarm gateway reaching its monitoring service, is allowed by policy at your gateway.
Is xPSK the same as the vendor features we already license?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple Access runs them from one platform on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring one wing's worth of devices: a nurse call hub, a pull-cord unit, a resident's tablet and an agency phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.