Case study — Building Infrastructure
Three separate systems — access control, network, billing — wired into one. No staff to reconcile them. No gaps between what someone owes and what they can reach.
The problem
Access control is from one vendor. The network from another. Billing lives in the ERP. When a membership lapses, someone has to notice — manually revoke the badge, manually suspend the wifi, manually chase the invoice. Between those manual steps, the gap is money lost and access you didn’t mean to grant.
System 01
Badges work as long as someone remembers to expire them. Late payment? Still has a working badge until IT gets the memo from finance — usually days later.
System 02
Every tenant gets a shared SSID. Nobody is isolated from anyone else. Overstayers keep connecting. There’s no signal when an account goes cold.
System 03
Staff cross-reference sign-in logs against invoices every month. Someone always misses a line item. The process takes two days and still produces errors.
What changed
| Dimension | Three separate systems | X402 integrated core |
|---|---|---|
| Account lapses | Badge still works until IT is manually notified — usually days late | Door lock enforced the moment billing expires — zero delay |
| Network access | Shared credentials; overstayers keep connecting indefinitely | Per-member VLAN provisioned on check-in, revoked on expiry or exit |
| Billing reconciliation | Two staff days per month cross-referencing sign-in logs by hand | Every session timestamped at the network layer — zero manual work |
| Security | Tenant A can reach Tenant B — flat network, no isolation | Every member on a separate segment — no lateral reach |
| Staff required | Dedicated person monitoring badge lists, network, and billing daily | Fully automated — staff handles exceptions, not the routine |
| Reliability | Single points of failure throughout | Redundant firewalls, switches, access points — everything has a failover |
How it works
802.1x / RADIUS
Every device is authenticated by the network itself via 802.1x before it gets an IP address. The RADIUS server queries the same member database the door controller uses — one source of truth for who is allowed what. No shared passwords; no shared VLANs.
Captive portal + ERP hook
When a member’s account status changes in the ERP — payment failed, plan expired, plan upgraded — the change propagates to both the network policy and the access controller in seconds. No cron job. No manual step. The captive portal simply stops granting access.
RFID + biometrics
Badge readers and biometric scanners feed the same access controller that talks to RADIUS. Issuing or revoking a member adds or removes them from both physical doors and network segments simultaneously — one action, both channels, immediate.
Redundant-everything architecture
Redundant firewalls in active-passive failover. Redundant core switches with spanning-tree backup paths. Redundant PoE access points with automatic client roaming. If any single device fails, the building continues without interruption — and staff are alerted before they notice.
X402 doesn’t sell a platform — we sell the outcome. That means picking the best hardware for each job without being locked into a single ecosystem. We’ve commissioned every class of firewall, network OS, and access control system in the trade. We combine what’s best for the site.
The same discipline that makes a zero-trust mesh self-defending applies here: every layer can fail without taking the next one down. The building keeps running. The logs keep recording. The billing keeps reconciling.
Ready to talk?
Whether you’re running a commercial campus, a co-working building, an industrial facility, or a corporate HQ — if you have access control, network, and billing that don’t talk to each other, we can wire them together. Tell us what’s breaking.