Skip to Content
Architecture

Architecture

Musterly connects to UniFi Access through a small local service called the Runner. The Runner keeps the UniFi host private while making the access data needed for safety workflows available in your Musterly workspace.

Components

ComponentWhere it runsResponsibility
UniFi AccessYour networkSource system for people, doors and access events
RunnerA Windows or Linux host on your networkMakes outbound connections to UniFi Access and Musterly
UniFi Access connectionStored in MusterlyHolds the saved connection configuration and assigns it to a Runner
Musterly workspaceMusterly cloudPresents Who’s In, safety-role coverage, roll calls and administration

“Connector” is the technical name for the saved Musterly configuration. In the product and these guides it is normally described as a UniFi Access connection.

Data flow

  1. An administrator creates a UniFi Access connection in Musterly.
  2. A Runner is installed on a machine that can reach the UniFi Access host.
  3. The Runner pairs with the correct Musterly workspace using a short-lived code.
  4. Musterly assigns the Runner to the saved connection.
  5. The Runner reads the configured UniFi data and sends the required records to Musterly over outbound HTTPS.
  6. A successful sync verifies the connection. A subsequent live badge event can then be selected as the commissioning event.

Runner and connection configuration can be completed in either order. Setup is only operational when they are assigned to one another and an end-to-end sync succeeds.

Network boundary

All cloud communication is initiated by the Runner. UniFi Access does not need to be exposed to the public internet, and Musterly does not open an inbound tunnel to the customer network.

For firewall destinations, host hardening and proxy guidance, see Networking and security.

Credentials and stored data

  • The UniFi credential is used only for the configured connection and should have the minimum permissions described in Connect UniFi Access.
  • Runner pairing codes are short-lived and single use.
  • After pairing, the Runner stores an environment-bound Runner token on its host.
  • Diagnostic status sent to Musterly is sanitised. It must not include raw credentials, bearer tokens or credential-bearing URLs.
  • Musterly stores the people, door, access-event and configuration data needed for enabled product features and administration.

For an exact data-retention or compliance requirement, contact your Musterly representative before production rollout.

Evaluation and production

For an evaluation, the Runner can run on a Windows PC if it stays powered on and can reach UniFi Access. For production, use a secured, supported, always-on Windows or Linux host with automatic startup and operational monitoring.

Last updated on