Work and commercial WiFi: a personal WiFi key for every tenant and device
The landlord owns the access points, each tenant owns its identity. Staff sit on EAP-TLS or directory groups, printers and building systems on keys, and visitors on the open network, with a VLAN or role per organization.
- 80% fewer IT helpdesk requests at McDonald's
- JPMorgan runs staff WiFi on Purple across 5,000 branches
- 80,000+ venues in 90 countries
Work and commercial
Work and commercial: pick your estate
Many organizations, one building: each company, member or retailer on its own network, on radios and an uplink the landlord runs once.
Coworking and flex space
A member company is a VLAN or role on shared access points, driven by the directory it already runs, so one set of radios carries many organizations and the operator keeps one log.Multi-tenant office buildings
The landlord owns the radios and the uplink and each tenant owns its identity: a VLAN or role per tenant on the landlord's access points, with building systems such as HVAC and access control in a lane of their own.Corporate offices
Certificates for every device that can hold one, a personal key for everything 802.1X cannot reach, and one directory driving joiners and leavers across all three networks.Shopping malls
Each retailer is its own merchant on the mall landlord's access points, so each gets its own VLAN and key set while shoppers stay on the portal and the center team keeps one log across every tenant.Retail chains
One VLAN, key and role template pushed to 5 stores or 5,000: every device class isolated by type, seasonal keys that end with the season, and no per-SSID key ceiling.
Use cases
The problems that thread these estates
Move-in and move-out without password changes
One resident leaves, one key is revoked, and nobody else is disconnected.IoT and devices with no screen
A device with no screen or certificate still gets its own MAC-bound key and VLAN.Contractors and visitors
Access that ends on its date: a portal for visitors, a time-limited key for contractors.Card payments and compliance
Payment and clinical devices on their own keys and VLANs, with a log to prove it.
FAQ
Questions IT leads ask
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Who owns what in a multi-tenant building?
The landlord owns the radios and the uplink, and each tenant owns its identity. One platform returns a VLAN or role per tenant, and a tenant that runs Entra ID, Okta or Google Workspace uses it as the identity behind its own staff WiFi.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.