WORKPLACE WI-FI ACCESS POLICY AND TEST RECORD Companion: https://yenra.com/secure-wifi-networking/ Prepared September 8, 2026. Use only for an authorized network and test endpoints. INSTRUCTIONS Describe each role's allowed work, necessary infrastructure services and denied destinations. Test the intended application connection. Verify the destination works from an allowed role before treating a failed restricted-role test as evidence of isolation. Keep credentials out of this worksheet. Organization / policy owner / version: Network diagram and configuration backup references: AP/controller and identity-service versions: Approved window / operator / rollback route: COPY PER ROLE Role and joining identity/device type: Enrollment method and assigned segment/role: Allowed applications and specific destination/protocol/port: Required address, DNS, time and enrollment services: Explicitly denied destinations: Rules enforcing the policy and administration path: Credential renewal / withdrawal / active-session handling: Exception, business owner and expiry condition: COPY PER TEST Timestamp and timezone / test device / assigned role: Destination and exact application connection: Address family (IPv4/IPv6 where enabled): Expected result: Positive control: allowed role, time and successful result: Restricted-role attempt and observed result: Supporting policy log / configuration evidence: Guest-to-guest check, if required: Management-interface denial check: Withdrawal/reauthentication test and observed delay: Correction and retest: ACCEPTANCE AND MAINTENANCE Unresolved exceptions / owner: Accepted scope / approver / date: Firmware, certificate-expiry and backup owners: Next trigger: new device class, application, site or identity service. Consult platform-specific authentication and filtering documentation linked in the companion guide; one denied test does not establish every possible boundary.