The Kadence Agent automatically checks people into their bookings when they arrive at the office. Enhanced Network Detection makes that far more accurate by reading two extra signals from a device — its internal IP address and the WiFi access point it's connected to — so the Agent can tell which building and floor someone is on.
It's most useful when several of your offices share one public internet connection, when employees connect over a VPN, or when you need floor-level presence data.
Key features
Accurate multi-site detection — tells your offices apart even when they share one public internet connection
VPN filtering — people working from home on your company VPN are no longer mistaken for being in the office, no VPN reconfiguration needed
Floor-level presence — shows which floor someone is on, not just which building — the foundation for floor-level analytics
Continuous presence — a "last seen" timestamp updates through the day, so you can see someone is still on-site, not just that they arrived
Set up safely, then go live — build your configuration with detection switched off, then turn on Enhanced Network Detection when you're ready
Backward compatible — nothing changes until you turn it on. Buildings with no signals configured keep working exactly as today
Cross-platform — works on Windows, macOS, Linux, and ChromeOS (IP-based detection only on ChromeOS)
Who can do this?
| Global Admin | Building Admin |
Configure Presence detection via WiFi for a building | Yes | Yes (their building) |
Add or edit floor connections (signals) | Yes | Yes (their building) |
Turn Enhanced Network Detection on or off | Yes | Yes (their building) |
Review conflicts and export booking data | Yes | Yes (their building) |
Employees don't need to do anything. Detection is invisible to them — they simply get more accurate automatic check-in. The one exception: on Macs, macOS shows a one-time Location Services prompt they need to allow for access-point detection.
Before you begin
The building already exists in Kadence, with its floors set up
The Agent is enabled for the building and its public IP is configured. If you haven't done this yet, see the Kadence Agent Setup & Management Guide
The Kadence Agent is rolled out to your employees and on the latest version
You have your network details on hand:
Internal IP subnets per floor, if you want floor-level detection by IP
WiFi access point identifiers (BSSIDs) per floor, if you want floor-level detection by access point
Your VPN client IP pool ranges, to confirm they don't overlap with office subnets
Your IT or network team will have most of this. There's a technical brief you can share with them ahead of setup — ask your Kadence contact for Enhanced Network Detection (for Customer IT).
Set up network detection
Network detection builds on your existing building setup. If you haven't enabled the Agent and set your building's public IP yet, do that first — see the Kadence Agent Setup & Management Guide. This guide picks up from there, at floor-level detection.
1. Open the Kadence Agent section in your Building Settings
Go to Building settings → Kadence Agent for the building
Expand Presence detection via WiFi
If the building inherits global settings, choose Override global settings to configure it on its own
2. Add floor connections
Under Floor connections, click Add connection
Choose the Floor the connection belongs to
Pick the Type — Internal IP / CIDR range or BSSID (WiFi access point)
Enter the Value — an internal IP range (for example
10.20.30.0/24), or a BSSID in MAC address format (for exampleAA:BB:CC:DD:EE:FF)
Each floor lists its connections in a Type / Value table you can edit at any time.
BSSID detection works on Windows, macOS, and Linux. ChromeOS uses IP-based detection only, so on ChromeOS set a separate internal IP range per floor for floor-level detection.
On Macs, Apple requires Location Services approval before the Agent can read WiFi access point details. Employees see a one-time macOS prompt they need to allow. Without approval, Macs quietly fall back to IP-based detection.
3. Turn on Enhanced Network Detection
While you're still adding signals, Enhanced Network Detection stays off so behavior doesn't change mid-setup. When your floors are configured, turn it on to go live.
Important: Once this is on, matching the building's public IP is no longer enough by itself — the device must also match one of your configured connections. That's what filters out VPN users, but it also means people on floors you haven't configured won't be auto-checked-in. Kadence shows you a banner for this — see Checking your configuration below.
How detection works
It's worth understanding the model so you can configure signals well. Detection is layered, and the public IP always comes first.
Public IP match. The device's public IP must match a configured building. If it doesn't, detection stops. (Kadence reads the public IP directly from the Agent's connection, so it can't be faked by the device.)
Building match. If the public IP matches a single building, that's the building. If it matches several buildings (offices sharing one internet connection), the internal signals work out which building the device is in.
Floor refinement. An internal IP that falls within a floor's range, or a BSSID mapped to a floor, resolves to that floor. If signals only match at building level, detection stays at building level.
When a device is on more than one network at once (for example, ethernet and WiFi), the signal from its primary connection takes priority. And when two signals on that primary connection point to different floors — say an internal IP and a WiFi access point — the access point wins, because it pinpoints one specific piece of hardware rather than a whole network range. Kadence flags the booking when this happens — see Checking your configuration below.
One thing to keep in mind: check-in only applies to a booking at the detected building. If someone is detected at a different building from their booking, the booking is left alone — none of its fields are touched.
Checking your configuration
The Floor connections panel does most of the verifying for you:
Floor coverage — the panel shows how many floors are active (for example, 2 of 7 floors active). If some floors aren't configured, you'll see a warning: people on those floors won't be auto-checked-in unless they match a building-level connection — see Rolling out network detection below for the safety-net approach. Add a signal to each floor to close the gap.
Signal conflicts — a Signal conflicts detected banner appears when two signals on the same device point to different floors — for example, its internal IP matches Floor 2 while its WiFi access point matches Floor 3. That almost always means a signal is mapped to the wrong floor. Kadence still checks the person in (the access point wins), but flags the booking so you can fix the mapping. Use Export booking data CSV to review the affected bookings.
On bookings themselves, you'll also see the detected floor and a last seen timestamp (updated on each successful detection, roughly every 15 minutes). These are available via the Kadence Booking API.
Rolling out network detection
You don't have to switch everyone over at once. Two behaviors make a staged rollout straightforward:
Older Agent versions keep working exactly as they do today — even after you turn Enhanced Network Detection on. Building-level detection uses the public IP of the Agent's connection to Kadence, which works the same on every Agent version. The updated Agent additionally reports internal signals — internal IP addresses, connection type, and the WiFi access point on supported platforms — and the stricter Enhanced Network Detection checks only apply to devices that report them.
A building-level connection acts as a safety net. A connection saved at Building level applies to the whole building, so anyone on your office network still checks in even if their floor's signals are missing or wrong — they're just detected at building level instead of floor level. VPN and home devices still match nothing and stay filtered out.
Step 1: Add a building-level safety net
In Floor connections, click Add connection, leave Floor set to Building level, and enter an internal IP range that covers your whole office network. With this in place, the worst outcome of a floor misconfiguration is losing floor-level detail — never a missed check-in. Just confirm your VPN client pool doesn't fall inside this range, or VPN filtering won't work.
Step 2: Update the Agent for a pilot group
Pick 10–20 people and roll the Agent update to just them. Aim for a spread: every floor represented, a mix of Windows, macOS, and ChromeOS, someone who works docked on ethernet, and at least one person who works remotely over VPN. On Macs, ask your pilot group to allow the one-time Location Services prompt that appears after the Agent update, so access-point detection works from day one.
Step 3: Turn on Enhanced Network Detection
Flip the toggle for the building. Everyone outside the pilot group carries on exactly as before.
Step 4: Verify with your pilot group
Give it a week or two and check:
On-site pilots are checked in, their bookings show the right detected floor, and last seen keeps updating through the day
Your remote VPN pilot is not checked in — this is the behavior the feature exists for, so test it deliberately
Your docked pilot is checked in. If not, that floor likely has only a WiFi access point configured — add the wired network's internal IP range too
No unexpected banners — watch the floor coverage indicator and the Signal conflicts detected banner, and fix any mappings it flags
Ask pilots to report any missed check-in. Each one points to a signal that needs correcting
Step 5: Roll out to everyone
Extend the Agent update to everyone else — in stages if you prefer — watching for missed check-ins as each group comes on board. Once you're confident in the per-floor signals, you can remove the building-level safety net for the strictest VPN filtering, or keep it permanently if your floors change often.
Work through one building at a time before extending across your estate.
Network detection settings
Presence detection via WiFi — the master section for a building, under Building settings → Kadence Agent. Off until configured.
Building connections — the building's public IP address(es). Set this up via the Kadence Agent Setup & Management Guide. Detects presence in the building, not the floor.
Floor connections — per-floor signals (internal IP ranges and/or BSSIDs), each shown in a Type / Value table. None configured by default.
Enhanced Network Detection — the go-live switch for floor-level detection. Off by default so you can finish setup first.
Frequently Asked Questions
Do I have to do anything if I'm happy with detection as it is today?
Do I have to do anything if I'm happy with detection as it is today?
No. Network detection is fully backward compatible. Buildings with nothing configured behave exactly as now (public IP only). You opt in by adding signals and turning on Enhanced Network Detection when you're ready.
Do employees need to update the Agent?
Do employees need to update the Agent?
Yes — it arrives as part of a normal Agent update through your usual channel (auto-update, MDM push, and so on). Until you turn on Enhanced Network Detection, behavior is unchanged.
Do I have to turn it on for everyone at once?
Do I have to turn it on for everyone at once?
No. Devices on older Agent versions don't report internal network signals, so they keep today's public-IP detection even with Enhanced Network Detection on. Roll the Agent update to a small group first, verify, then extend — see Rolling out network detection above.
What happens to people on a VPN?
What happens to people on a VPN?
They're correctly treated as off-site. A device connected to your VPN gets its internal address from the VPN, not from your office network, so it won't match any of your configured connections and won't be auto-checked-in. Just make sure the addresses your VPN assigns don't overlap with the office ranges you configure.
Floor detection isn't working for our Chromebooks — why?
Floor detection isn't working for our Chromebooks — why?
ChromeOS doesn't expose the BSSID to the app, so access-point detection isn't possible there. Internal IP detection still works, so you can get floor-level detection on ChromeOS by setting a separate internal IP range per floor. Otherwise, ChromeOS devices detect at building level.
On Macs, what's the Location Services permission about?
On Macs, what's the Location Services permission about?
Apple requires Location Services before an app can read WiFi access point details. The Agent uses it only for that — no GPS or geolocation. Employees see a one-time macOS prompt after the Agent update; if it's declined, the Mac quietly falls back to IP-based detection.
We replaced a WiFi access point and detection got coarser. What happened?
We replaced a WiFi access point and detection got coarser. What happened?
When an access point's hardware changes, its BSSID can change too, so it no longer matches your configured value. If that floor also has an internal IP signal, detection still works via IP; if the BSSID was the only floor signal, those devices fall back to building-level detection. No errors — just update the value in Floor connections.
Someone who docks on ethernet isn't being detected — why?
Someone who docks on ethernet isn't being detected — why?
A docked laptop with WiFi off only presents its wired connection, so a floor configured only with WiFi access points won't match it. Add the floor's wired network as an Internal IP / CIDR range connection and it will be detected normally.
Why aren't some floors being detected?
Why aren't some floors being detected?
Check the floor coverage indicator in Floor connections. Any floor showing Not configured won't get WiFi check-in once Enhanced Network Detection is on — add a signal to each floor you want covered.
Does it check people out when they leave?
Does it check people out when they leave?
No. There's no auto-checkout. Last seen records the most recent confirmed presence; it isn't a departure time.
Are internal IPs and BSSIDs personal data?
Are internal IPs and BSSIDs personal data?
No — they're network infrastructure identifiers. The Agent reads only internal IPs, connection type, the connected BSSID, and which connection the device is actively using. It doesn't read network names (SSIDs), DNS, traffic, or browsing data. All traffic to Kadence is over HTTPS, and configuration is scoped to your tenant. The technical brief covers this in full for your security team.
How is this different from badge or access-control check-in?
How is this different from badge or access-control check-in?
They complement each other. Badge and turnstile integrations detect physical entry and need an integration with your access vendor; network detection picks up the device joining the office network, gives floor-level granularity, and keeps confirming presence through the day. Many customers use both.
Need Help?
For support, reach out to:
📩 [email protected]
For more helpful articles see:
📚 Kadence Help Center







