Education & Public Sector

Guest WiFi for Central Government

Access that leaves the day they do.

A contractor's WiFi access should end the day their contract does — most departments can't prove it does. We fix that over the access points you already own, from the team behind 430+ South African venues. Staff sign in against the department's own directory — Entra ID, Google Workspace or Okta — with access revoked within minutes the moment a record is disabled. A visitor lane runs its own branded, POPIA-compliant portal, on a segment that never touches the network staff and case systems sit on. And the same setup can do more — the session record an audit asks for is already there, logged as it happens, not assembled the night before.

Trusted on Purple worldwide
Proven on Purple, shipping today

The zero-trust, audit-ready WiFi Purple already proves

Staff access syncs to the department's own directory, and every connection is logged for audit — proven mechanisms on the platform running 80,000+ venues, doing the work a department's audit trail demands.

Staff sign in without a shared password

Passwordless Zero-Trust access integrates with Microsoft Entra ID, Google Workspace and Okta, with certificate-based 802.1X from the first connection — no password for a leaver to take with them.

Access revoked in minutes, not days

Disabling a record in the department's own directory revokes WiFi automatically, across every site, within minutes — Purple's proven Staff WiFi mechanism.

A visitor lane that never touches staff systems

A branded captive portal signs the public in on its own segment, isolated from the network carrying staff and case systems — a guest lane, not a security exception.

Every session logged as it happens

Session logging (RADIUS accounting) records session start, end and data transferred as it happens — the record an audit asks for already exists, not assembled after the fact.

Compliant by design

ISO 27001 / 9001 certified, GDPR / POPIA-aligned, with hosting on-premise, private cloud or hybrid — wherever a department's own compliance requires.

And the same login can do more than connect. Step inside for ten seconds.

Step inside the engine

The ten seconds your visitor never notices.

Back in the daylight

Your visitor never noticed the tech. Your team never lifted a finger.

Staff access that provisions and revokes itself against the department's own directory, a visitor lane that never touches it, and a session log already sitting there before the audit asks for it — over the access points already installed.

On the ground in South Africa

Deployed, integrated and supported on the ground

Beyond runs and supports live WiFi estates across South Africa — deployed, integrated and kept POPIA-compliant on the ground, not from a call centre in another timezone. Your central government run on the same team that keeps 430+ venues online.

430+venues live across South Africa
40+enterprise estates managed
6 yrson the ground in South Africa
9sectors served

Across our estates we've delivered 11.9M+ guest logins and 1.9M+ POPIA-compliant opt-in records — first-party data that turns a login into a relationship.

Built on Purple — the platform trusted by some of the world's biggest brands, proven across 80,000+ venues in 90+ countries. We make that foundation yours.

What Beyond adds — the art of the possible

What Beyond adds with the department's own directory and its audit calendar

The first-time visitor at the counter

They connect while waiting for a branded welcome; Beyond can wire that welcome to the counter's own queue system, so it names the desk and the ticket number, not a generic homepage.

The applicant renewing a licence

Recognised from last year's visit, not handed the same form again. Beyond can wire that match to the department's own licensing system, so a renewal status is one tap away, not a phone call.

The caseworker

Signs in against the department's own directory — no shared password, no login book at the front desk. The moment their access is disabled, the network follows within minutes.

The compliance officer

Beyond can turn RADIUS's own session log into the audit-ready report an inspection actually asks for — who connected, when, for how long — pulled in minutes, not assembled the week before.

What you don't replace

You keep the department's own case-management system, its directory and the access points already installed across the building. Beyond wires in zero-trust sign-in and a separate visitor lane — no forklift upgrade, no new network to run.

Straight answers

Frequently asked

Does a staff member need a separate password for WiFi?

No — sign-in runs against the department's own directory (Entra ID, Google Workspace or Okta), the same one used everywhere else.

How fast is access revoked once someone leaves?

Within minutes. Disabling the record in the directory revokes WiFi automatically, across every site — no shared password to change.

Does the visitor lane ever touch staff or case systems?

No — it runs on its own segment, isolated from the network carrying staff and case-management systems.

Can we prove who was on the network, and when, for an audit?

Yes — RADIUS accounting logs every session as it happens (start, end, data transferred), so the record exists before an auditor asks for it.

Where can the data be hosted?

Wherever compliance requires — on-premise, private cloud or hybrid — with ISO 27001 / 9001 certification and GDPR / POPIA alignment built in.

Your venue, your story

See staff access that revokes itself, and a session log ready before the audit.

Book a 30-minute walkthrough and leave with a mapped rollout for your directory, your visitor lane and your next audit.