Network and Device Counting
Counting people by counting their devices. Cheap, already installed, and wrong in ways that are hard to correct.
Methods · Analysis
Wireless access points already know how many devices are associated with them. Turning that into an occupancy figure is tempting and unreliable.
The technical evidence in “Network and Device Counting” describes the building, while the effort required to install, test and maintain it is project work. When teams research employee monitoring at tech companies, employee monitoring at tech companies can provide time and project context for that operational effort without replacing the sensor platform as the source of truth for physical occupancy.
What it sees
Devices connected to each access point, with rough location by signal strength.
For a public, independent reference related to “Network and Device Counting”, consult the NPSA protective-security guidance. Its principles provide a useful check on scope, terminology, governance and the claims made during procurement or review.
Over time, which gives movement patterns across a building.
At no additional hardware cost, which is the main attraction.
Why the numbers are wrong
People carry different numbers of devices. One, two or three, and the mix differs by role and by floor.
Devices persist after people leave: a laptop left on charge counts all night.
Devices roam. One phone can associate with several access points, counted each time unless deduplicated.
Access points have overlapping coverage, so the boundary between zones is fuzzy by metres.
And guests, contractors and building systems all appear in the same count.
The correction factor trap
The standard fix is a device-per-person ratio, derived once and applied thereafter.
That ratio is unstable: it differs by floor, by day of week, and it drifts as device policy changes.
Applying a fixed factor produces a number with a plausible shape and unknown error, which is worse than an obviously rough figure because it invites confidence.
Where it is genuinely useful
Relative change over time in one building: this floor is busier than last quarter.
Movement and flow between zones.
Large-scale patterns where precision does not matter.
Not: headcount, room sizing, or anything feeding a financial decision.
The privacy dimension
Device identifiers are personal data in most regimes, even when the device is not named.
Modern devices randomise their addresses, which breaks tracking and also breaks the counting method — a known and growing problem for this approach.
Anything retaining identifiers to follow a device across zones is movement tracking, and should be treated as such in consultation and in the data protection assessment.
Doing it defensibly
Aggregate at the access point, retain counts rather than identifiers.
Deduplicate roaming devices explicitly and document the method.
State the device ratio you used and when it was derived.
And validate against a manual count at least once, which usually tempers the confidence appropriately.
What to check
Do you know your device-per-person ratio, and when it was measured?
Are roaming devices deduplicated?
Are identifiers retained, and for how long?
And has the figure ever been checked against people counted by hand?