Free artifact · From the McAllen build
The Rapid Large-Scale AP Deployment Checklist
The checklist I wish I'd had on day one of a 60-day, 1,000-AP citywide build. Free to use, steal, and adapt — just tell people where it came from.
The Rapid Large-Scale AP Deployment Checklist
In 2020, my hometown of McAllen, Texas asked me to help get the whole city online — 1,000+ access points, 24 CBRS base stations hanging off water towers, city light poles as vertical real estate, Federated Wireless handling SAS, cnMaestro holding it all together, and $3.1 million in CARES Act money with a use-it-or-lose-it clock ticking. We had 60 days. We made it, but I'll be honest with you: a lot of what follows is stuff we figured out at 2 a.m. in a staging warehouse, not stuff we knew walking in. This is the checklist I wish I'd had on day one. I'll keep refining the numbers as I go back through my notes and as folks send me their own war stories — treat the specifics as a starting point, not gospel.
Phase 1: Before You Sign Anything
- Confirm the actual deadline and what "done" means in writing. "Deployed by December 30" can mean powered-on, passing traffic, or invoiced — those are three different projects, and CARES-style funding deadlines don't slip.
- Identify the single person who can say yes. A citywide build touches IT, public works, traffic, legal, and utilities; if you don't have one empowered decision-maker, every pole becomes a committee meeting.
- Get pole and vertical-asset agreements signed before you order gear. Light poles, traffic signals, and water towers each have different owners, load ratings, and attachment rules — the paperwork takes longer than the mounting.
- Verify who owns the poles you think the city owns. Some "city" poles belong to the electric utility, and their attachment process runs on utility time, not your timeline.
- Confirm power availability at every pole class, not every pole. Photocell-switched poles are dark all day; you need to know which circuits are always-hot before your design assumes 24/7 power.
- Decide the power tap method and get it blessed by the electrical inspector once, up front. One approved detail drawing beats 1,000 individual arguments about how you're pulling power off a luminaire.
- Map backhaul reality before promising coverage. Every AP cluster needs a path home — fiber, licensed PTP, or CBRS — and the sites with the best coverage are often the ones with the worst backhaul.
- Lock the funding rules: what's reimbursable, what documentation is required, and when. Grant money comes with receipts, serial-number-level asset reporting, and audit exposure years later.
- Establish who owns and operates the network after day 60. If the answer is "we'll figure it out," you're building an orphan.
- Get structural sign-off for water tower and elevated assets early. Tank climbs need certified crews, sometimes drain-downs or coordination with water ops, and the scheduling lead time is weeks.
- Confirm insurance, bonding, and prevailing-wage requirements for every crew type. Public money means public procurement rules, and a crew that can't badge in is a crew that can't hang radios.
- Write the escalation path down. When a bucket truck blocks a lane at 5 p.m. or a resident calls the mayor about "5G towers," you need to know who answers the phone in the first hour.
Phase 2: RF & Network Design
- Design the backbone and the edge as two separate networks that happen to share poles. In McAllen that meant CBRS base stations on water towers feeding Wi-Fi APs on light poles — different physics, different failure modes, different planning tools.
- Pick your elevated sites first and let them drive everything else. Water towers are the best free vertical real estate in most cities; 24 base stations set the sectors, and the sectors set where the APs could live.
- Do the CBRS SAS planning before you assume spectrum. Register with your SAS provider (we used Federated Wireless), understand GAA vs. PAL in your county, and model what happens when incumbent protection claws back a channel mid-deployment.
- Build a channel and PCI/frequency reuse plan for the CBRS layer on paper before the first radio ships. Two dozen base stations in a flat city will hear each other; plan the reuse like a cellular engineer, not a Wi-Fi guy with a bigger antenna.
- Model Wi-Fi coverage for the client you're actually serving. A kid on a school Chromebook in a living room 150 feet from a light pole is your design target — not a phone held up in the street under the AP.
- Accept that outdoor-to-indoor Wi-Fi is a compromise and design the expectation, not just the RF. Publish where service works (porch, yard, near-window) so the coverage promise matches the physics.
- Standardize on as few hardware SKUs as you can survive with. Every additional model is another firmware train, another spare pool, and another config template to keep honest.
- Design the IP plan for the finished network, not the pilot. Carve address space by base station sector and AP cluster from day one; renumbering 1,000 devices later is a project nobody funds.
- Separate management, backhaul, and user traffic logically end to end. VLANs or tunnels, your call — but a user should never be able to reach a base station's management plane, full stop.
- Decide your SSID, captive portal, and authentication strategy once, citywide. One SSID, one policy, one portal — a patchwork of per-neighborhood configs is unmanageable at this scale.
- Plan content filtering and legal compliance for a public network up front. CIPA-style filtering expectations, lawful intercept questions, and acceptable-use policy all need answers before launch, not after the first incident.
- Size the internet handoff and core for concurrent evening load. A homework network peaks at 7 p.m., all at once, all pulling video.
- Engineer for the failure of any single tower site. Know which neighborhoods go dark when one water tower's backhaul dies, and decide whether that's acceptable before it happens.
- Write the RF design down as a living document with a change log. Sixty days of field reality will amend your desk study daily, and the amended version is the one operations inherits.
Phase 3: Supply Chain & Staging
- Place the hardware order the same hour the funding clears. Lead time is the one schedule risk you cannot crew your way out of; everything else on this list can be parallelized.
- Order 5–10% overage on everything, including the boring stuff. APs get DOA'd, mounts get dropped from bucket trucks, and nobody stocks your exact banding hardware locally on a Saturday.
- Kit every pole as a unit, not a parts list. One box per pole — AP, mount, band clamps, power tap, patch cable, weatherproofing, zip ties, label — so a crew never leaves a site missing one $2 part.
- Stand up a staging facility with power, bench space, and real internet. You are about to boot, upgrade, and configure a thousand devices; a warehouse with two 15-amp circuits and a hotspot will not do it.
- Solve the 1,000-unit provisioning problem with zero-touch, or it will eat your schedule alive. We leaned on cnMaestro onboarding so a device claimed at the bench pulled its config and firmware itself — hand-configuring at scale is how 60 days becomes 120.
- Pin one firmware version per SKU and pre-load it at the bench. Field crews should never wait on a firmware download over freshly-lit backhaul, and a mixed-firmware fleet is a debugging nightmare.
- Bind serial number, MAC, asset tag, and destination pole ID at the bench, in one scan pass. Barcode it once into a shared tracker; this single habit is what makes grant audits, RMAs, and troubleshooting survivable.
- Pre-name devices by site before they leave the building. "AP-0417-N23rd-and-Fern" in the controller beats "cnPilot-a4f3" times a thousand.
- Burn in every unit powered-on at staging, even if just overnight. Infant-mortality failures are far cheaper to catch on a bench than 30 feet up a pole.
- Track chain of custody from bench to truck to pole. Gear walks. A sign-out sheet per kitted box, per crew, per day keeps everyone honest and tells you instantly what's on which truck.
- Stage consumables by the pallet: weatherproofing, banding, connectors, labels, PPE. The $30,000 radio waits on the $0.30 part more often than the other way around.
- Set up an RMA fast lane with your vendor before you need it. Advance replacement with a local depot of spares means a bad unit costs you an hour, not a week. Being close with the Cambium team didn't hurt us one bit.
Phase 4: Crews & Cadence
- Do the math backwards from the deadline and post it on the wall. 1,000 APs in 60 days is roughly 17 per day with zero days off — so if a crew hangs 8–10 a day, you need two to three crews running plus a catch-up buffer.
- Split crews by skill: tower crews, pole crews, and a roving fix-it crew. The people certified to climb a water tower are wasted banding APs to light poles, and vice versa.
- Route each crew's day geographically the night before. Windshield time is the silent killer of your per-day number; clustering installs by neighborhood can double effective output.
- Run a mandatory morning stand-up and evening count. Ten minutes each: what's assigned, what got hung, what got skipped and why. The skip list is your real schedule.
- Define a QA gate a crew must pass before leaving each site. AP checked in to cnMaestro, correct name, correct firmware, photo of the mount, photo of the weatherproofing — no green checks, no next site.
- Put one person on remote QA watching the controller while crews are in the field. They confirm each install online in real time and radio the crew before the bucket truck drives away — a return visit costs 10x the original install.
- Photograph everything and file it by pole ID. Mount, drip loop, power tap, serial plate, and a wide shot; you'll use these for audits, warranty claims, and settling "your crew broke this" disputes.
- Give crews a laminated one-page install standard, with pictures. The drip loop, the tape wrap order, the mount torque — decided once, drawn once, followed a thousand times.
- Plan traffic control and lane closures as part of routing, not as a surprise. Some poles need a lane taken; batch those on the same days with the same permits and the same cones.
- Build weather days into the cadence math. South Texas will hand you lightning, 105-degree heat, and the occasional tropical system; a schedule with zero slack is a schedule that's already blown. I learned that one during Harvey.
- Rotate the miserable work. Sixty straight days breaks people; protecting your crews' bodies and morale is a schedule-protection activity, not a kindness.
- Track a single burn-down chart everyone can see. Installed, online, QA-passed — three lines, updated daily. If "installed" and "QA-passed" diverge, you're building technical debt at 17 sites a day.
Phase 5: Commissioning & Monitoring
- Commission tower sites and backhaul before the APs that depend on them. An AP with no path home is street furniture; sequence the build so the core is always ahead of the edge.
- Verify SAS grants for every CBRS radio and log them. Confirm each base station has its spectrum grant, note the channel and power, and watch for grant suspensions during the first weeks.
- Define "commissioned" as a measured test, not a green LED. A speed test from a client device at the design edge of coverage, a captive portal walk-through, and a DNS/filtering check — per cluster, every time.
- Load-test the portal and DHCP scopes before launch day. The first evening a whole neighborhood connects at once is the wrong time to find out your scope was a /24.
- Build monitoring dashboards before launch, not after the first outage. cnMaestro gives you fleet-wide health out of the box; add alerting for AP offline, base station offline, and backhaul degradation with different severities — one dead AP is a ticket, one dead tower is a page.
- Baseline everything in week one. Client counts, per-sector throughput, channel utilization, retransmits — you can't spot "abnormal" later if you never recorded "normal."
- Sweep for the silent failures weekly. An AP that's online but serving zero clients in a populated neighborhood is broken in a way no red alarm will tell you.
- Document as-builts as you commission, not at the end. Pole ID, GPS, serials, photos, config version — captured the day it goes live, because nobody remembers site 400 by day 59.
- Run a punch-list pass through every neighborhood before declaring it done. Drive it, connect from the sidewalk, and fix the stragglers while crews and momentum still exist.
- Keep a formal exceptions list of sites that couldn't be built as designed. Every skipped or relocated pole changes the coverage map; the ops team and the public map both need the truth.
Phase 6: Day-2 Operations & Community Comms
- Hand operations a runbook, not a phone number. Top ten failure modes, how to spot each in the dashboard, and the fix — written by the people who built it, while they still remember.
- Set up a public-facing status and coverage map. Residents shouldn't have to guess whether the network is down or they're out of range; the map answers half your support calls before they happen.
- Stand up a real support intake with a triage script. "No internet" from a resident could be their device, the portal, an AP, or a tower — a two-minute script sorts which before a truck rolls.
- Publish plain-language instructions for connecting, in English and Spanish. In McAllen, bilingual flyers, school district channels, and local media did more for adoption than any press release. This network existed so kids could do homework — meet the families where they are.
- Brief city council and city staff on what the network is and isn't. The people residents call first need honest talking points about coverage limits, filtering, and privacy before launch day.
- Schedule preventive maintenance like it's real, because it is. Quarterly weatherproofing spot checks, firmware review windows, and an annual tower inspection — outdoor gear in Texas sun and storms ages fast.
- Fund and stock a spares pool as a line item. A defined percentage of the fleet sitting on a shelf, pre-provisioned, turns a two-week outage into a two-hour swap.
- Track adoption and usage monthly and report it upward. Client counts, data served, neighborhoods active — this data is what defends the operating budget and justifies expansion.
- Close the loop on grant compliance with a final asset and expenditure report. Every serial number, every invoice, every pole — filed before the auditors ask, because with federal money they will ask.
- Do a written lessons-learned within 30 days of launch. This checklist exists because we did the sloppy version of one; the sharp version makes your next 60-day build a 45-day build.
- Decide the refresh and expansion roadmap while the wins are fresh. The network you launched is the network you'll be defending, growing, and re-justifying for the next five years — start that conversation the week after the ribbon-cutting, not the year after.
That's the list. If you're staring down your own compressed-timeline build — municipal, festival, stadium, whatever — steal every bit of this, and then send me what I got wrong. That's how the list gets better.
Based on the McAllen citywide deployment. I refine this as I run more builds — suggestions welcome at drew@drewlentz.com.