Overview
The Threat Intelligence dashboard provides real-time visibility into risks that may impact your workplace locations. From a single place, admins can watch active threats update live on an interactive map, see exactly who is in the impact area, and take immediate action when needed.
The dashboard is powered by more than 1,000 verified sources, spanning authoritative government feeds, hyper-local city emergency alerts, and local news. An AI-powered intelligence layer scores every signal for relevance and confidence, dedupes across sources, and surfaces only the threats that matter to your locations and your people.
The Threat Dashboard works out of the box for every existing location, but you can connect to your HRIS for more enriched employee data. To receive active notifications about threats, be sure to set up proactive alerting.
All threats on the dashboard can be automatically loaded into an Emergency notification incident for quick sharing with employees and visitors.
See your assets anywhere in the world
Your people are your most important asset, and the threat intelligence dashboard allows you to layer on additional data to offer a more complete picture of employee locations.
VIPs: You can designate high-priority individuals, such as executives, so you can immediately see when a threat is near someone critical. Learn more about designating VIPs.
Homes: Integrate with your HRIS to show employees homes on the Threat Dashboard, giving a more complete view of potential risk areas. Exact addresses are never visible apart from VIPs. Learn more about displaying homes.
Travelers: employees who are away from their home base and on the move. Available soon with Navan integration.
The map and your live threat feed sit side by side in a split view, so you can scan active threats and their locations together. Select Expand map for a full-screen view when you want to explore a region in detail.
Threat sources
The Threat Dashboard combines two layers of sources.
Always-on authoritative sources:
National Weather Service (NWS) & NOAA — US weather alerts
MeteoAlarm — European weather alerts
FEMA — federal emergency declarations
USGS — US seismic alerts
US State Department — travel advisories
ReliefWeb — global travel advisories
FAA alerts — airport issues and grounded flights
GDELT — global news
AI-discovered dynamic sources:
In addition to typical government sources, the Threat dashboard integrates local news RSS feeds and police blotter feeds from the top 100 metros worldwide. These are surfaced automatically based on your workplace locations, so there is nothing to configure.
AI relevance and confidence scoring: an AI layer scores every incoming signal for relevance to your workplace and confidence in the source, then dedupes and correlates signals across feeds. Only events that clear the relevance threshold appear on the dashboard.
Have a source in mind? Let your account representative know or contact support.
Threat categories
Crime & Violence: Violent or threatening incidents with area-wide or ongoing impact. Individual resolved crimes are excluded; they only surface if there is an active threat to employees or the surrounding area.
Civil Unrest: Large-scale public disorder affecting safe movement or access to facilities.
Transit & Transportation: Disruptions to ground, air, or rail travel affecting employee commutes or business logistics.
Infrastructure & Hazmat: Physical failures or hazardous incidents at or near facilities, including industrial incidents at nearby sites.
Global Security: Acts of terrorism or credible security threats with a local, physical impact near assets.
Travel Risk & Advisories: Government-issued advisories or geopolitical instability affecting international employee travel or operations abroad.
Public Health: Disease outbreaks or contamination events affecting travel, office operations, or public safety.
Weather: Meteorological events causing immediate or near-term safety or operational risk.
Environmental Hazards: Geological or ecological events with physical impact on assets or the surrounding area.
Using the Threat intelligence dashboard
Web
When reviewing an active threat, admins can click the threat to view more details and send an incident message through Envoy.
Navigate to Response > Threat intelligence
By default, all threat levels will be shown. You can filter severity and category by using the dropdowns in the top right corner.
You can toggle Map layers, displaying VIPs or Homes by using the toggle in the upper left corner. You won't see this option if you haven't enabled home addresses.
Active threats appear in a live feed next to the map. Each threat has an associated radius, which, alongside Envoy data, determines the people affected.
People: The total number of individuals affected by the alert.
Building: The total number of on-site employees and visitors at a workplace location.
House: The number of employee homes affected by the threat.
Travelers: The number of traveling employees in the threat radius.
VIP: Total number of designated VIPs in the threat radius. This can be their home address, a travel location, or an on-site status at a workplace location.
The + and - buttons on the right side of the map zoom in/out. The threat radius will respond accordingly. You can click and drag to explore different areas. Clicking the
button will center the map back to your workplace location.
Viewing a threat and creating an incident
To view more details of a threat, click the threat or the Details button.
To create an incident and send a message, click the Create incident button.
This will open a New incident message form, pre-populated with information from the selected threat.
You may need to truncate the message, as messages are limited to 320 characters.
From here, the process is the same as sending an incident notification on Web: Ask recipients to respond, take over screens, select recipients, and delivery methods.
The incident will be marked as an Emergency message, and recipients will be asked to respond.
By default, the Employee checked in to [location], Visitors signed in, and Visitors invited but not signed in, will be selected. These are people determined as impacted by the threat.
All available Delivery methods will be selected.
Click Send Now to send your message. Sending creates an active incident in your Incident log.
Mobile
Available on iOS v.5.39.0+ and Android v.5.22.0+
Open the Envoy app. Scroll down to Threat intelligence, under More to explore.
By default, all alerts are shown.
You can tap the filter buttons in the upper-right-hand corner to set your severity level, category, and VIPs and Homes.
The + and - buttons in the bottom-right corner of the map zoom in/out. The threat radius will respond accordingly.
Viewing a threat
To view details of a threat, tap anywhere on the threat.
This will open a description and list of those impacted.
To send an incident message and notify impacted people, click Create incident.
From here, the process is the same as Sending a notification on mobile: Ask recipients to respond, take over screens, select recipients, and delivery methods.
Click Send Now to send your message. Sending creates an active incident in your Incident log.










