No mandatory SaaS access
Core workplace functions must continue without relying on an external scheduling service.
Regulated and secure environments
Operate flexEZ inside customer-controlled infrastructure, including fully air-gapped environments, with a standalone scheduling engine and locally connected workplace devices.

Controlled operations
Teams still need clear booking and workplace coordination when internet access and external services are restricted.
Core workplace functions must continue without relying on an external scheduling service.
Application, device and integration traffic may need to remain inside the managed network.
Identity, Exchange and operational systems may also be installed inside the isolated environment.
Access, booking and administration rules often require sector- or site-specific adaptation.
Where control matters
The required level of isolation varies. Some sites need a fully air-gapped system; others need customer-controlled hosting, integrations and data paths to satisfy governance and risk requirements.
Operational sites where workplace systems may run on restricted or disconnected networks.
Why control matters
Network classification, mission continuity and attack-surface reduction can prohibit reliance on public cloud or internet connectivity.
Organizations handling sensitive programs, facilities and supply-chain relationships.
Why control matters
Contractual security obligations, controlled technical information and customer accreditation can require tightly governed hosting and network routes.
Institutions operating critical services under extensive security, resilience and audit obligations.
Why control matters
Third-party risk, data governance, business continuity and change-control policies may favor infrastructure and integrations the institution can directly govern.
Enterprises that manage sensitive personal, commercial or operational information.
Why control matters
Privacy, residency, retention, auditability and internal security policies may require clear ownership of where data is stored and how systems communicate.
Public-sector workplaces managing citizen services, sensitive records or essential administrative functions.
Why control matters
Sovereignty requirements, procurement rules, records governance, continuity obligations and security classification may require government-controlled hosting and explicit data paths.
Keep the user experience and connected devices within the boundaries defined by the organization.
Use configured local identity, directory or access-control arrangements.
The standalone engine manages resources, availability and booking policies.
Tablets and supported occupancy sensors communicate with the flexEZ server.
Authorized teams use local schedules, status and analytics for decisions.
Combine standalone operation with the hardware and management functions appropriate to the site.
Run core flexEZ services within infrastructure controlled by the customer.
Provide a complete local booking experience across workplace resources.
Use tablets that communicate with flexEZ without requiring an external source.
Connect supported 3D people-counting and Atlona OCS sensors using local addresses.
Use booking, status and sensor data within the controlled deployment.
Connect supported devices and operational data through local integration patterns.
Where approved, a custom integration can exchange authorized-user or reservation-derived lists with a local physical security system—for example, allowing a door or controlled zone to open only for eligible people during approved times.
A controlled deployment must serve employees and operators without weakening the organization’s architecture boundaries.
Use a clear scheduling experience within the approved environment.
Control hosting, identity, network paths, updates and integration boundaries.
Manage resources, room devices, policies and local workplace data.
The final design should reflect the organization’s network classification, identity and operational-support requirements.
Operate the standalone engine and local endpoints without external network access.
Connect to an Exchange environment installed within the same controlled network.
Allow only the explicitly approved integrations and network routes.