6.8mediumCONDITIONAL GO

Office Presence Detection API

A network-aware presence detection service that confirms employee office attendance without relying on IdP session mechanics.

DevToolsHybrid workplace ops teams and HR departments enforcing return-to-office poli...
The Gap

Using IdP login events as a proxy for physical office presence is fragile—sessions persist, apps bypass SSO, and workarounds annoy remote staff. Companies need reliable presence detection for hybrid work policies.

Solution

An agent on managed devices (leveraging existing MDM) that detects office network connection via WiFi BSSID/IP range and fires a webhook to check-in systems (Envoy, Robin, etc.), completely decoupling presence detection from authentication flows.

Revenue Model

Freemium: free for up to 50 users, subscription at $3-5/user/month for larger orgs with analytics and integrations.

Feasibility Scores
Pain Intensity7/10

Real pain confirmed by the Reddit thread and broader RTO enforcement trends. However, it's primarily felt by workplace ops/HR teams—not the end users. Many orgs muddle through with badge data or manual check-ins. The pain is acute for the segment enforcing RTO with consequences (bonus adjustments, performance reviews) but mild for orgs that just want soft nudges.

Market Size6/10

TAM is narrower than it appears. Target is hybrid orgs with MDM-managed devices AND enforced RTO policies AND dissatisfaction with current check-in methods. Estimated 50K-100K mid-to-large companies globally fit this profile. At $3-5/user/month with avg 200 users = $7.2K-12K ARR per customer. Realistic SAM is $50M-200M. Not a billion-dollar market, but viable for a bootstrapped or seed-stage startup.

Willingness to Pay5/10

This is the weakest link. Workplace ops budgets are often squeezed. $3-5/user/month competes with tools like Envoy that offer broader functionality at similar price points. Many orgs will ask 'can't IT just script this from our MDM data?' Badge systems already exist in most offices. The buyer (HR/ops) may see this as a nice-to-have unless RTO compliance has C-suite visibility and consequences.

Technical Feasibility8/10

Core MVP is straightforward: a lightweight agent (macOS/Windows) that checks WiFi BSSID or IP range against a configured list and fires a webhook. Leveraging MDM for deployment simplifies distribution. A solo dev could ship a working macOS agent + basic API + Envoy webhook in 4-6 weeks. Challenges: Windows service signing, cross-platform parity, handling VPN edge cases, battery/performance impact. macOS privacy permissions for WiFi BSSID access (CoreLocation) require user consent, which MDM can pre-approve.

Competition Gap8/10

Clear white space. No product offers passive, vendor-agnostic, client-side network presence detection that maps to individual employees and integrates with check-in systems. Cisco/Aruba do passive WiFi detection but require their infrastructure and don't map to employees. Envoy/Robin require manual action. MDMs have the data but no one has productized it. This is a genuine gap.

Recurring Potential8/10

Natural SaaS fit. Per-user/month pricing with ongoing value (daily presence data, analytics, compliance reporting). Retention should be strong once integrated into HR workflows and compliance processes. Expansion revenue from analytics tier, multi-site support, and integration add-ons.

Strengths
  • +Clear competitive white space—no one has productized passive, vendor-agnostic network presence detection
  • +Leverages existing MDM infrastructure, so no new hardware and low deployment friction
  • +Technically feasible MVP in 4-6 weeks for a solo dev with systems programming experience
  • +Strong tailwinds from enforced RTO mandates at large companies
  • +API-first approach enables integration with existing workplace tools rather than replacing them
Risks
  • !Willingness to pay is uncertain—buyers may view this as a feature of their MDM or workplace platform, not a standalone product
  • !OS privacy restrictions are tightening: macOS requires Location Services permission to read BSSID, and future OS updates could further restrict access
  • !Political risk: employees may resist being 'tracked' and push back, creating internal friction for the buyer
  • !Platform risk: Envoy, Robin, or MDM vendors (Jamf, Intune) could ship this as a native feature with minimal effort
  • !Small initial market if only targeting orgs with both MDM and enforced RTO policies
Competition
Envoy

Workplace platform for visitor management and employee check-ins via mobile app, iPad kiosk, or badge tap. Added desk booking and capacity tracking.

Pricing: Free tier for basic visitor management; paid plans $3-5/employee/month; enterprise custom
Gap: No passive network-based detection—requires manual check-in every time. Presence is event-based, not continuous. Gets expensive at scale and is primarily a visitor tool with attendance bolted on.
Robin

Workplace management platform for desk booking, room scheduling, and occupancy analytics via reservations and optional hardware sensors.

Pricing: $3-6/user/month (Team/Business/Enterprise
Gap: No WiFi/network-based detection. Presence is inferred from bookings, not actual physical attendance. Deploying sensors adds major cost and logistics overhead.
Cisco DNA Spaces (Meraki Location Analytics)

Enterprise location analytics on Cisco WiFi infrastructure. Detects devices on the network via WiFi trilateration, provides occupancy heatmaps and dwell time.

Pricing: Bundled with Cisco Meraki licensing (substantial
Gap: Complete vendor lock-in to Cisco WiFi. Extremely expensive. Identifies MAC addresses, not employees—requires separate device-to-user mapping. MAC randomization degrades accuracy. Complex to deploy.
Density

Hardware sensor platform using proprietary overhead depth sensors to measure real-time room and floor occupancy by counting bodies.

Pricing: Hardware $2,000+ per sensor plus SaaS subscription for Density Atlas analytics; enterprise contracts
Gap: Cannot identify WHO is present—only headcount. Useless for individual attendance tracking or RTO compliance. Expensive hardware installation at every entry point.
Jamf Pro / Microsoft Intune (MDM platforms)

MDM platforms that collect device inventory including connected SSID, IP address, and network info from managed devices. Not designed as presence tools, but the raw data exists.

Pricing: Jamf: $4-12/device/month; Intune: included in Microsoft 365 E3/E5 or $8/user/month standalone
Gap: No attendance or presence feature built on this data. No webhook to check-in systems. Requires custom scripting/ETL to turn inventory reports into presence events. Polling-based, not real-time. No one has productized this capability.
MVP Suggestion

macOS agent (Swift, distributed via MDM profile) that reads current WiFi BSSID on network change, matches against configured office BSSIDs, and fires a webhook to Envoy or a generic endpoint. Simple admin dashboard (Next.js) for configuring office networks, viewing daily presence logs, and managing webhook destinations. Start with a single integration (Envoy) and one platform (macOS) to validate demand before expanding.

Monetization Path

Free for ≤50 users (single site, basic webhook) → $3/user/month Pro (multi-site, analytics dashboard, Slack notifications) → $5/user/month Enterprise (SSO, audit logs, custom integrations, compliance reporting exports). Land with IT/workplace ops teams at mid-market companies already using Envoy. Expand via HR buyer once compliance reporting is built.

Time to Revenue

8-12 weeks. 4-6 weeks to build macOS agent + basic API + Envoy integration. 2-4 weeks for initial customer discovery and pilot with 2-3 companies from sysadmin/IT communities (Reddit r/sysadmin, MacAdmins Slack). First paying customer likely month 3-4.

What people are saying
  • Okta sessions expire on network/IP change
  • users spend the whole day without ever hitting Okta, so no check-in fires
  • causing frustration especially for remote workers
  • I think our office uses badge-in for Envoy check-ins... you only care about a check in