01

Choose a business action, not a device catalogue

Occupancy, indoor-environment, energy and room data only matter when they change a decision. Define the action first: adjust operating hours, investigate a comfort issue, release space, prioritise maintenance, compare branches or report an agreed indicator.

User and action

Identify who receives the information, the decision they make and the response time required.

Measurement fit

Confirm that the chosen sensor, location, interval and accuracy are suitable for that decision.

Outcome boundary

State what the data can indicate and what needs separate professional assessment or investigation.

02

Map the integration chain and responsibility

Document the chain from field device to the person acting on the result. For each hop, record the supplier, interface, protocol, network path, credentials, licence, data owner, support owner and acceptance evidence.

BACnet is an established building-automation communications standard intended to support vendor-independent interoperability. Protocol choice is useful, but successful integration still requires compatible profiles, point definitions, tested mappings and agreed system behaviour.

Physical layer

Device, location, mounting, power, containment, labelling and maintainable access.

Connectivity layer

Gateway, addressing, network segment, firewall path, bandwidth, resilience and time source.

Application layer

Point model, API or protocol mapping, identity, permissions, dashboard, alerts and export.

Operating layer

Monitoring owner, incident route, maintenance window, warranty, renewal and end-of-life plan.

03

Build cyber and privacy controls into the scope

Connected workplace devices create new access paths and data responsibilities. HKCERT describes IoT security across perception, network, management and application layers, and recommends considering security throughout design and development.

Minimise and segment

Collect only necessary data, place devices in approved network zones and restrict flows to documented destinations.

Control access

Remove defaults, use named administration, define vendor remote access and retain access logs where required.

Operate securely

Record firmware ownership, vulnerability response, backup, certificate or credential renewal and secure disposal.

Review people data

Assess whether occupancy, location or identity data can identify individuals and involve the appropriate privacy owner.

04

Accept the service, not isolated components

Device-level checks prove that parts are alive. Integrated acceptance proves that the intended workplace response works. Test normal, boundary, offline, recovery and permission scenarios, then hand over one issue and ownership register.

Traceability

Every dashboard value traces to a device, point name, unit, timestamp and transformation rule.

Failure behaviour

Prove how the service reports stale data, lost connections, failed devices and platform outages.

Change control

Document who can add points, change thresholds, update integrations and approve releases.

Sources

Primary references

These primary sources were used to check public requirements, the purpose of standards or recognised practice. Project-specific applicability must be confirmed.

FAQ

Frequently asked questions

Is IoT a separate UPNX service or part of a wider project?

It can be either. For most corporate workplaces, IoT is most valuable when coordinated with electrical, network, AV, security, BMS and project-delivery responsibilities rather than installed as an isolated package.

Does using BACnet guarantee interoperability?

No. BACnet supports vendor-independent interoperability, but compatible implementation, point definitions, profiles, network design, security and tested sequences are still required.

Who should own smart-workplace data after handover?

The client should name a business data owner and operational support owner. Contracts should state access, retention, export, hosting, account administration and what happens when a vendor changes.