Overview
The Navan integration connects your company's corporate travel data to Envoy. Once connected, employees' business trips booked in Navan flow into Envoy automatically, giving your security and workplace teams visibility into where your people are when they are on the road.
This visibility powers traveling employee protection on the Threat Dashboard. Traveling employees appear on the map based on their active trip, are counted in the impacted totals for each active threat, and can be reached directly when a threat lands near them.
Without a travel connection, Envoy has no signal that an employee is traveling for business, so travelers can fall outside your normal location-based coverage. Learn more about traveling employee protection and the Threat Intelligence dashboard.
PREREQUISITES
An admin account in Navan with permission to authorize third-party connections.
Enabling Envoy + Navan
Step 1: Generate API credentials in Navan
Create these in Navan under Travel > Settings > Integrations.
Find the Navan API Credentials and create a new API credential. Learn more on Navan's Help Center.
If Navan offers a scope or permissions option, choose read-only (bookings:read and users:read). That is all this integration needs, and it cannot push changes to your Navan account.
Optional: Navan supports restricting API access to specific IP addresses. You can skip this, or use Envoy's public IPs (
18.204.164.109,52.6.210.64, and52.86.90.108) for this field.
Copy the Client ID and Client Secret. Keep them somewhere safe for step 2 (a password manager is ideal).
Step 2: Connecting Navan to Envoy
Log in to your Envoy dashboard, then navigate to Integrations. Search for Navan, then click Install.
Click Authorize.
Click Connect Account to launch the configuration window.
Enter your Client ID and Client Secret from Navan.
Select your data Region.
Click Save.
Ongoing sync
After the initial backfill, Envoy automatically keeps travel data current. New trips, changes, and cancellations in Navan appear in Envoy within about an hour. You don't need to run or refresh anything manually. Past trips are not archived in Envoy. Once a trip's dates pass, Envoy removes the trip data from the Threat Intelligence dashboard.
You can disconnect or reconnect the integration at any time from the integration's settings in your Envoy dashboard.
About travel data
Envoy ingests only the trip information needed to place travelers on the map and account for them during a threat.
Each synced trip includes:
Trip name and start and end dates.
Flight segments (airline, flight number, departure and arrival airports, timing).
Hotel information (name, location, and stay dates).
Location and coordinate data for each segment, used to plot travelers on the map.
Envoy matches trips to employees by work email address. Envoy excludes sensitive traveler details, such as passport and payment information, when it ingests data.








