Case study — Building Infrastructure

When the membership expired, the door stopped opening.

Three separate systems — access control, network, billing — wired into one. No staff to reconcile them. No gaps between what someone owes and what they can reach.

~1,000 users per day
across 3 buildings
0 billing exceptions
per month
24/7 unattended
operation
100% automated
reconciliation

The problem

Most buildings run three systems that never learned to talk to each other.

Access control is from one vendor. The network from another. Billing lives in the ERP. When a membership lapses, someone has to notice — manually revoke the badge, manually suspend the wifi, manually chase the invoice. Between those manual steps, the gap is money lost and access you didn’t mean to grant.

System 01

Access control — on its own island

Badges work as long as someone remembers to expire them. Late payment? Still has a working badge until IT gets the memo from finance — usually days later.

System 02

Network — completely uncoupled

Every tenant gets a shared SSID. Nobody is isolated from anyone else. Overstayers keep connecting. There’s no signal when an account goes cold.

System 03

Billing — reconciled by hand

Staff cross-reference sign-in logs against invoices every month. Someone always misses a line item. The process takes two days and still produces errors.

Integration Layer — Live
Event trigger
badge:— waiting…
Access Controller RFID reader — door lock controller
IDLE
Network Policy 802.1x / RADIUS — per-member VLAN
IDLE
Billing Engine ERP hook — session start / stop
IDLE
Event log

What changed

Same building. One integrated system instead of three disconnected ones.

Dimension Three separate systems X402 integrated core
Account lapses Badge still works until IT is manually notified — usually days late Door lock enforced the moment billing expires — zero delay
Network access Shared credentials; overstayers keep connecting indefinitely Per-member VLAN provisioned on check-in, revoked on expiry or exit
Billing reconciliation Two staff days per month cross-referencing sign-in logs by hand Every session timestamped at the network layer — zero manual work
Security Tenant A can reach Tenant B — flat network, no isolation Every member on a separate segment — no lateral reach
Staff required Dedicated person monitoring badge lists, network, and billing daily Fully automated — staff handles exceptions, not the routine
Reliability Single points of failure throughout Redundant firewalls, switches, access points — everything has a failover

How it works

The integration is not a feature. It’s the architecture.

802.1x / RADIUS

The network authenticates, not just the door

Every device is authenticated by the network itself via 802.1x before it gets an IP address. The RADIUS server queries the same member database the door controller uses — one source of truth for who is allowed what. No shared passwords; no shared VLANs.

Captive portal + ERP hook

Billing enforced by the infrastructure

When a member’s account status changes in the ERP — payment failed, plan expired, plan upgraded — the change propagates to both the network policy and the access controller in seconds. No cron job. No manual step. The captive portal simply stops granting access.

RFID + biometrics

Physical and digital access from the same record

Badge readers and biometric scanners feed the same access controller that talks to RADIUS. Issuing or revoking a member adds or removes them from both physical doors and network segments simultaneously — one action, both channels, immediate.

Redundant-everything architecture

No single point of failure, full stop

Redundant firewalls in active-passive failover. Redundant core switches with spanning-tree backup paths. Redundant PoE access points with automatic client roaming. If any single device fails, the building continues without interruption — and staff are alerted before they notice.

Vendor-agnostic. Redundancy-first. Open where possible.

X402 doesn’t sell a platform — we sell the outcome. That means picking the best hardware for each job without being locked into a single ecosystem. We’ve commissioned every class of firewall, network OS, and access control system in the trade. We combine what’s best for the site.

The same discipline that makes a zero-trust mesh self-defending applies here: every layer can fail without taking the next one down. The building keeps running. The logs keep recording. The billing keeps reconciling.

Ready to talk?

Automate your building or campus.

Whether you’re running a commercial campus, a co-working building, an industrial facility, or a corporate HQ — if you have access control, network, and billing that don’t talk to each other, we can wire them together. Tell us what’s breaking.

Start the conversation Email directly
More from X402
Industrial IoT

4,073 machines. 21 factories. 40 days to first pilot live.

Payment Rails

3.4-second settlement. Three banks. 35,000 customers.

Precision Agriculture

500+ drones. Not one pilot. Every acre surveyed from the air.

Zero-Trust Network

6,000+ endpoints. Not one breach made it past the front door.

Government & Tax

14 federal APIs. One compliance engine. Zero audit failures.