GDS Technology — Built, Wired and Secured podcast banner
Watch on YouTube →
Episodes Wired
Episode 103

Airwaves & Endpoints: Mapping the Invisible IoT Layer in Commercial Buildings

August 8, 2026
Key takeaways
  • Undocumented wireless and IoT endpoints can create outages, tenant friction, and security exposure.
  • A practical discovery program should start with passive network evidence and low-impact RF scanning.
  • Physical walkthroughs are essential because many problem devices are small, hidden, and never documented.
  • Ownership should follow operational risk, with joint participation from facilities, IT, and property management.
  • Quarterly scans, device registration, and contract controls help prevent the same issues from returning.

Show Notes

Why the Invisible Radio Layer Matters

In this episode of Built, Wired, and Secured, Alex Morgan sits down with Michael Harrington and James Rogers to unpack a problem that is easy to overlook in commercial buildings: the undocumented wireless and IoT devices that quietly accumulate over time. The conversation starts with a realistic failure scenario. A third-party gateway installed earlier for vendor sensors begins backfilling traffic and takes part of a building automation segment offline during a busy weekday. HVAC performance becomes unreliable, the help desk gets flooded with calls, and it takes far too long to locate the offending device.

The point is clear from the opening minutes: these are not abstract technical issues. When undiscovered radios fail or interfere with systems, tenants feel the impact immediately through comfort problems, service disruptions, escalations, and avoidable downtime. As the guests explain, reliability begins with disciplined maintenance, and no team can maintain what it has never properly inventoried.

What Counts as an Invisible Endpoint?

Michael lays out a practical map of what teams should be looking for. Invisible endpoints can include:

  • BAS sensors and wireless thermostats
  • Vendor gateways used for metering or analytics
  • Tenant IoT devices such as smart lighting and meeting room sensors
  • Cellular boosters
  • Bluetooth beacons
  • Vendor-managed Wi-Fi extenders

These devices pile up because projects are segmented and ownership is fragmented. IT may own the network, facilities may own building systems, vendors may manage their own hardware, and tenants may introduce convenience technology without a formal handoff. The result is a growing radio layer that is operating in the background but missing from asset records.

The episode also highlights a common source of friction: tenants or vendors can install small devices that blend into the environment, often powered from a standard outlet and placed in closets or comms rooms. Nobody notices until something breaks, and then the investigation turns into emergency troubleshooting.

How to Discover These Devices Without Blowing the Budget

One of the most useful takeaways in the episode is that discovery does not have to begin with an expensive toolkit. James recommends a layered approach that starts passive and scales only where needed.

  • Review network-side evidence such as DHCP leases, ARP tables, and SIS logs to identify devices touching the infrastructure.
  • Perform passive RF scans using a spectrum analyzer or phone-based Wi-Fi and Bluetooth scanners to detect transmissions without disconnecting anything.
  • Conduct a physical walkthrough with a tablet and checklist, focusing on vendor closets, tenant comms rooms, and spaces above ceilings.
  • Request installed device lists from vendors, since many will provide records when asked directly.

The guests emphasize that a low-cost baseline survey can find the obvious transmitters. A more advanced calibrated analyzer should be reserved for anomalies or locations with recurring problems. They also advise teams to prioritize areas where outages hurt the most, including data centers, mechanical plants, and tenant floors supporting 24/7 operations.

There is also a strong operational caution here: passive first, active only when necessary. Active testing should be scheduled during low-impact windows, especially in sensitive environments. The episode shares the hard-earned lesson that active sweeps in spaces like hospital wings during peak hours can create unnecessary risk.

Who Owns the Problem?

Ownership is often where radio-layer projects stall. Is it a facilities issue, an IT issue, or a property management issue? The answer in this episode is practical: ownership should track risk, not org charts.

If building operations are the primary concern, facilities may need to lead. If network integrity is the main exposure, IT has to be deeply involved. If tenant behavior or lease requirements are part of the issue, property management also needs a seat at the table. The workable model described by the guests is joint ownership with one accountable lead.

That lead should stay focused on a simple guiding question: what breaks if this goes down? The discussion makes the case that tenant service continuity is usually the first metric to protect. If tenants cannot operate, every other performance target becomes secondary.

Real-World Fixes That Stopped Repeat Outages

The episode includes two practical examples that show how small interventions can produce immediate results.

In one site, building automation lag led to deeper investigation. Passive network scans revealed unusual traffic from a vendor gateway sitting on a tenant VLAN. A walkthrough located the small gateway in a tenant closet, where it was auto-updating and flooding the switch. The remediation steps were straightforward:

  • Move the device to a managed VLAN
  • Apply rate limits
  • Add contract language requiring device registration

Once those controls were in place, the outages stopped and tenants noticed the improvement.

In another example, a tenant-installed cellular booster interfered with the building environment. A targeted RF walk found the source, the team coordinated removal, replaced it with approved infrastructure, and followed up with tenant education. That combination of immediate mitigation and governance helped prevent the issue from recurring.

The Starter Checklist for Building Teams

For listeners ready to start, the episode closes with a concise checklist that can shape a discovery project:

  • Scope the project by identifying critical building areas and systems, especially mechanical plants, comms rooms, and tenant floors with 24/7 operations.
  • Collect passive discovery artifacts such as DHCP, ARP, and SIS logs.
  • Run a baseline RF walk on high-traffic floors and mechanical rooms using simple tools first.
  • Request vendor-installed device lists and confirm remote management access.
  • Apply immediate mitigations by quarantining unknown devices, rate-limiting traffic, and communicating with tenants before removals.
  • Establish governance through required device registration, contract language, quarterly scans, and radio inventory in capital planning.

The guests also stress the value of pairing building-systems knowledge with radio expertise during walks. One specialist alone can miss what a cross-functional pair will catch quickly.

Final Takeaway

This episode frames undocumented wireless endpoints as an operations and governance issue, not just a technical nuisance. The invisible radio layer affects uptime, tenant experience, troubleshooting speed, and security posture. The practical message is to start small, stay passive where possible, protect tenant operations first, and assign one accountable lead with cross-team support. In commercial buildings, connected systems only stay controllable when somebody is actively accounting for the radios behind them.

Deeper dive

The Wireless Devices You Cannot See Can Still Disrupt the Entire Building

Commercial buildings now depend on a growing mix of connected systems that extend far beyond traditional wired infrastructure. Building automation sensors, thermostats, vendor gateways, cellular boosters, Bluetooth beacons, meeting room sensors, and Wi-Fi extenders all support day-to-day operations. But as discussed in this episode of Built, Wired, and Secured, many of these endpoints never make it into formal asset records.

That gap creates a serious operational problem. A small undocumented device can trigger outages, degrade tenant experience, complicate troubleshooting, and introduce avoidable risk. In the episode, Alex Morgan talks with Michael Harrington and James Rogers about how teams can discover and manage this invisible radio layer without turning the process into an expensive, disruptive project.

Why Undocumented Endpoints Create Real Business Risk

The conversation opens with a scenario that captures the problem clearly. A third-party gateway that had been installed months earlier for vendor sensors starts backfilling traffic and knocks a building automation segment offline during a busy weekday. HVAC performance becomes inconsistent, the help desk gets overwhelmed, and the team spends an hour just locating the device.

That example matters because it shows how quickly an overlooked endpoint turns into a business issue. Tenants do not experience the problem as a network anomaly or asset-management failure. They experience it as comfort complaints, service degradation, delays, escalations, and uncertainty about whether building systems are under control.

From an operational standpoint, the message from the episode is simple: undocumented radios are live risk. They do not have to be malicious to cause disruption. They only have to be unmanaged.

What Makes the Radio Layer So Hard to Track?

One of the strongest points in the episode is that invisible endpoints accumulate through normal business activity. Different projects bring in different devices. A vendor installs a gateway for analytics. A tenant adds convenience technology. A small cellular booster gets dropped into a closet to solve a signal problem. A wireless extender appears as part of a one-off request. Each individual decision may seem reasonable in isolation.

The trouble is that ownership is split. IT owns the network. Facilities owns building systems. Vendors own their devices. Property management may oversee tenant expectations and rules. Tenants themselves may engage outside vendors. In that environment, inventory handoff often fails. Devices stay in service, but accountability gets blurry.

The episode makes a practical observation here: many of these devices are physically easy to miss. They are small, often powered from a standard outlet, and tucked into closets, comms rooms, or other low-visibility spaces. They blend in until they become a problem.

Start Discovery with Evidence You Already Have

For teams that want to get ahead of this issue, the guests recommend a layered discovery model. The first step is not to buy a large toolkit or overengineer a survey. It is to start passive and work from existing evidence.

On the network side, DHCP leases, ARP tables, and SIS logs can reveal devices that are already touching the environment. Those records help establish a baseline of known and unknown endpoints interacting with infrastructure.

On the air side, passive RF scanning can identify active transmissions without disconnecting anything or causing disruption. The episode points to tools like a basic handheld spectrum analyzer or a smartphone with Wi-Fi and Bluetooth scanning capabilities as practical starting points. For many buildings, this is enough to surface obvious transmitters and begin organizing the work.

That matters from a budget standpoint. The guests argue that teams do not need to begin with a high-end, calibrated analyzer everywhere. A lower-cost baseline survey can uncover the biggest problems first. More advanced tooling can then be reserved for anomalies, interference issues, or spaces with recurring trouble.

Why the Physical Walkthrough Still Matters

Digital artifacts alone are not enough. The episode reinforces the importance of walking the building with a tablet and checklist. Vendor closets, tenant comms rooms, under-ceiling spaces, and similar locations often contain the exact devices that never made it into the official record.

There is a strong operational lesson in how these walks should be staffed. The guests recommend pairing someone who understands building systems with someone who understands radios. That combination improves results because each person sees different clues. A building-systems specialist may recognize what belongs operationally, while a radio-focused person may spot an unexpected transmitter or configuration pattern faster.

This cross-functional pairing is especially useful in commercial environments where the impact of failure is tied to how a space is actually used. The technical scan only becomes valuable when it is connected to operational context.

Prioritize Based on What Breaks First

Not every square foot of a building carries the same level of operational exposure. The episode recommends prioritizing data centers, mechanical plants, and tenant floors that support round-the-clock operations. Healthcare suites, labs, and trading-floor-like environments deserve special attention because the cost of disruption is higher.

The practical filter the guests use throughout the conversation is this: what breaks if this goes down? That question helps teams avoid boiling the ocean. It shifts the project away from abstract completeness and toward service continuity.

In most cases, the first metric to protect is tenant uptime. If tenants cannot operate, the consequences spread quickly across support, facilities, management, and vendor relationships. That makes prioritization clearer and keeps the project grounded in business outcomes.

Ownership Should Follow Risk, Not the Org Chart

A common failure point in projects like this is the question of who owns the work. Facilities may assume IT should lead because radios touch the network. IT may push back because the devices support building systems. Property management may only become involved once tenants complain.

The episode argues for a more workable approach: joint ownership with one accountable lead. Facilities can lead when operational impact is primary. IT must remain involved where network controls and segmentation matter. Property management needs to help enforce tenant-related rules and communication. The key is not perfect org-chart clarity. The key is making one person accountable for answering the question of what breaks if the device fails.

That structure helps prevent the classic situation where everyone touches the issue but nobody truly owns the outcome.

Small Fixes Can Deliver Immediate Stability

The real-world examples in the episode show that remediation does not always require a major rebuild. In one case, passive scans found unusual traffic from a vendor gateway on a tenant VLAN. A walkthrough then located the device in a tenant closet, where it was auto-updating and flooding the switch. The corrective actions were practical: move it to a managed VLAN, apply rate limits, and require device registration in contract language. The result was immediate improvement and fewer tenant-facing disruptions.

In another case, a tenant-installed cellular booster was creating interference. A targeted RF walk identified it. The team coordinated removal, replaced it with approved infrastructure, and followed up with tenant education. That sequence is worth noting because it combined short-term technical mitigation with longer-term governance.

That is one of the clearest business lessons from the episode. Stability does not come from finding the device alone. It comes from making sure the same problem does not quietly return later.

A Practical Starter Checklist

For organizations that want to begin without overcomplicating the effort, the episode offers a concise checklist:

  • Define scope by building area and critical systems.
  • Identify high-priority zones such as mechanical plants, comms rooms, and 24/7 tenant floors.
  • Collect passive network artifacts like DHCP, ARP, and SIS logs.
  • Perform a baseline RF walk using simple Wi-Fi, Bluetooth, or spectrum-scanning tools.
  • Request vendor-installed device lists and validate remote access arrangements.
  • Quarantine unknown devices where appropriate and apply traffic limits to reduce exposure.
  • Communicate with tenants before device removal or changes.
  • Require device registration in contracts and operational processes.
  • Run periodic quarterly scans and include radio inventory in capital planning.

Make Discovery Part of Operations, Not a One-Time Cleanup

The long-term takeaway from this conversation is that discovery should become a recurring discipline. Quarterly scans, required device registration, clear contract language, and a named lead all help keep the radio layer visible and manageable.

For commercial real estate teams, that is the real value of the episode. It does not present wireless and IoT discovery as a specialty exercise for rare incidents. It presents it as part of building reliability, tenant experience, and operational governance.

If your building environment includes wireless systems that support comfort, convenience, monitoring, or connectivity, the question is not whether the invisible radio layer exists. It does. The real question is whether your team has a repeatable way to find it, document it, control it, and respond before it becomes the reason tenants notice something is wrong.

To hear the full conversation and walk through the discovery and governance approach in more detail, listen to the full episode of Built, Wired, and Secured.