Groups and security flavours
An EasyPSK group maps one Wi-Fi key to a set of devices. The security flavour — Instant, Approved, or Dedicated — sets how strict device onboarding is, and is locked once the group has its first device.
A group in an EasyPSK Context maps one Wi-Fi pre-shared key to a set of devices — up to 30 devices per group. When you create the group you choose how strict device onboarding should be — you can dial it up later, but only while the group still has no devices.
Creating a group
Section titled “Creating a group”Open the Context and click Add Group. The form has two parts:
- Identity — the Group name, shown to admins and used to label devices that join with this group’s key.
- Security flavour — a three-position slider. Slide to balance friction against security; the choice is locked once the group has its first device.
The three flavours
Section titled “The three flavours”| Instant | Approved | Dedicated | |
|---|---|---|---|
| Tagline | Frictionless | Pre-registered | Per-device key |
| Key model | One group key | One group key | A unique key per device |
| Device onboarding | Auto-registered on first connect | MAC must be pre-registered; a correct key is otherwise rejected. Optional four-eyes approval | MAC pre-registered together with its unique key; both must match |
| Best for | Friction-free co-working and residential units | Groups where only known devices may join | The strictest environments and headless fleets |
- Instant — devices connect with the group key and are auto-registered: no pre-registration. Best for friction-free co-working and residential use.
- Approved — devices must be pre-registered. A correct key is rejected unless the device’s MAC is already registered in the group. With four-eyes device approval enabled, a second administrator must also acknowledge each registration.
- Dedicated — a unique key per device. Pre-register the device’s MAC; both the MAC and the device’s own key must match at connect time. There is no shared group key at all.
The platform generates every key. Keys are unique within the EntryPoint and regenerate-only: users never choose them. The key is what identifies the group at connect time — “one key, the right group”.
Four-eyes device approval
Section titled “Four-eyes device approval”On Approved groups you can require that each device registration is acknowledged by a second administrator before the device is admitted. The first administrator registers the device’s MAC; the device stays pending until another administrator approves it, and until then it is rejected at connect time even with the correct key. Use it where device admission is a controlled decision: finance floors, labs, or any environment where one person should not be able to admit hardware alone.
Beyond the flavour: group controls
Section titled “Beyond the flavour: group controls”Each group also carries a set of group controls: a device cap, a validity window, a recurring schedule, and a device block list. They apply on top of the flavour, so a correct key only admits a device that also passes the group’s controls.
The group page
Section titled “The group page”Each group has stat cards (Users — self-service members, Devices — registered in the group, Online) and five tabs: Connected Devices, MAB Device List, Self-Service Users, Group Settings, and Authentication Log.
Group Settings
Section titled “Group Settings”
- Security flavour — shows the group’s flavour. It stays editable until the first device connects, then locks.
- Pre-shared key (Instant and Approved) — the group’s key, masked with Reveal and Copy controls. Regenerate PSK disconnects every device still using the current key; they reconnect with the new one.
- Per-device keys (Dedicated) — there is no shared group key to reveal or regenerate. Each device has its own unique key, managed from the device list.
- Self-service PSK regeneration — a toggle that lets the group’s Self-Service members rotate the shared key themselves from the Self-Service portal. For Dedicated groups the toggle does not apply, since rotation happens per device.
Self-Service
Section titled “Self-Service”Invite residents or team members from the Self-Service Users tab. From the Self-Service portal they can see the SSID and their group’s key, and — if you enabled self-service regeneration — rotate it. In Dedicated groups, device keys are issued and rotated per device instead.