01
Choose a business action, not a device catalogue
Occupancy, indoor-environment, energy and room data only matter when they change a decision. Define the action first: adjust operating hours, investigate a comfort issue, release space, prioritise maintenance, compare branches or report an agreed indicator.
User and action
Identify who receives the information, the decision they make and the response time required.
Measurement fit
Confirm that the chosen sensor, location, interval and accuracy are suitable for that decision.
Outcome boundary
State what the data can indicate and what needs separate professional assessment or investigation.
02
Map the integration chain and responsibility
Document the chain from field device to the person acting on the result. For each hop, record the supplier, interface, protocol, network path, credentials, licence, data owner, support owner and acceptance evidence.
BACnet is an established building-automation communications standard intended to support vendor-independent interoperability. Protocol choice is useful, but successful integration still requires compatible profiles, point definitions, tested mappings and agreed system behaviour.
Physical layer
Device, location, mounting, power, containment, labelling and maintainable access.
Connectivity layer
Gateway, addressing, network segment, firewall path, bandwidth, resilience and time source.
Application layer
Point model, API or protocol mapping, identity, permissions, dashboard, alerts and export.
Operating layer
Monitoring owner, incident route, maintenance window, warranty, renewal and end-of-life plan.
03
Build cyber and privacy controls into the scope
Connected workplace devices create new access paths and data responsibilities. HKCERT describes IoT security across perception, network, management and application layers, and recommends considering security throughout design and development.
Minimise and segment
Collect only necessary data, place devices in approved network zones and restrict flows to documented destinations.
Control access
Remove defaults, use named administration, define vendor remote access and retain access logs where required.
Operate securely
Record firmware ownership, vulnerability response, backup, certificate or credential renewal and secure disposal.
Review people data
Assess whether occupancy, location or identity data can identify individuals and involve the appropriate privacy owner.
04
Accept the service, not isolated components
Device-level checks prove that parts are alive. Integrated acceptance proves that the intended workplace response works. Test normal, boundary, offline, recovery and permission scenarios, then hand over one issue and ownership register.
Traceability
Every dashboard value traces to a device, point name, unit, timestamp and transformation rule.
Failure behaviour
Prove how the service reports stale data, lost connections, failed devices and platform outages.
Change control
Document who can add points, change thresholds, update integrations and approve releases.
Sources
Primary references
These primary sources were used to check public requirements, the purpose of standards or recognised practice. Project-specific applicability must be confirmed.
FAQ
Frequently asked questions
Is IoT a separate UPNX service or part of a wider project?
It can be either. For most corporate workplaces, IoT is most valuable when coordinated with electrical, network, AV, security, BMS and project-delivery responsibilities rather than installed as an isolated package.
Does using BACnet guarantee interoperability?
No. BACnet supports vendor-independent interoperability, but compatible implementation, point definitions, profiles, network design, security and tested sequences are still required.
Who should own smart-workplace data after handover?
The client should name a business data owner and operational support owner. Contracts should state access, retention, export, hosting, account administration and what happens when a vendor changes.