Overview
Presence integrations let Envoy automatically record who is on-site, from a badge swipe, a network connection, an SSO login, a managed device, or a phone crossing a geofence. This is a passive way employees are checked into the office; there's no app to open or kiosk to tap.
That matters beyond occupancy counts. Presence data informs your on-site policy reports, emergency notifications, and space-planning decisions. If you capture data manually, it may be incomplete, and incomplete data is a problem during an evacuation, not just at quarter-end.
This article covers the systems Envoy integrates with and how to choose among them. To control which signals Envoy accepts and how sign-outs work, see Presence Control Center.
Video: What is Presence?
Why Presence matters
Presence integrations are effective because they don't depend on people remembering. Manual check-in may only capture a fraction of the people actually in the building. Presence signals come from systems employees already use to get through the door, onto the network, or into their apps.
Duty of care. During an incident, you need to know who is on-site — not who booked a desk. Presence feeds Emergency Notifications and Emergency Roll Call, so your recipient list reflects who is actually in the building.
Security and awareness. Badge, MDM, authentication, and network signals surface in the Access log as a live stream of workplace activity, giving security teams a single view of employee movement alongside visitor activity.
Compliance. Organizations working under trade-control, national-security, or site-access restrictions need a defensible record of who was on-site and when.
What Presence powers
Capibility | How Presence is used |
Measures adherence to RTO requirements against real attendance, not bookings | |
Populates attendance records and shows which signals are capturing the most presence | |
Rolls occupancy up across all sites | |
Grounds map and footprint decisions in actual utilization | |
Builds the on-site recipient list and the accounted-for roll call list | |
Prompts hosts to release booked rooms if meeting attendees have not been detected on-site | |
Automatically frees up booked hotel desks if the employee is not detected by a set time. | |
Occupancy in non-owned spaces | Get insight into co-working spaces by capturing presence at these non-owned locations |
Choosing your signals
Presence signals are not equally reliable. Most workplaces should lead with the strongest available signal and add others for coverage.
Because no single signal is complete, Envoy recommends enabling more than one and using a Multi-signal policy where accuracy matters most.
Please note that if you integrate these systems with Envoy Visitors, you'll need additional setup for employee auto-check-in.
Physical Access Control (ACS)
These integrations use badge swipe events from your access control system to mark an employee as on-site the moment they tap into a secured door. Envoy ingests the badge event and automatically updates the employee’s presence, ensuring accuracy based on real physical entry. We recommend these strong signals for any site that uses a compatible ACS. Combine this signal with at least one other, since tailgating means some employees may enter your workplace without a badge event.
Integrations include:
SSO
Envoy uses identity-based access control signals from your SSO provider and matches the login activity against the known IP ranges of your workplace. When an employee signs in via Okta or Entra ID from within the office network, Envoy automatically records their on-site presence for that day. This signal is best for offices with stable, known public IP ranges.
Integrations include:
VPN use from employee homes can place a login inside your IP range; split-tunnel and remote-access setups need review before enabling this for presence detection.
Network Access Control
These integrations detect presence when an employee’s device connects to the corporate network or Wi-Fi. As soon as Envoy receives the authenticated connection event from the NAC provider, it marks the employee as on-site.
Integrations include:
Mobile Device Management
When a managed device reports activity through Jamf (such as a login, startup, or network connection), Envoy evaluates those signals to determine whether the device is on your office network. If those signals match your configured office location, Envoy can automatically mark the employee as on-site. This is a very strong signal, and useful if your company has fleets of managed laptops. If employees tend to use personal devices, you'll want to combine this method with at least one other.
Geolocation
Employees with the Envoy mobile app can be checked in automatically when their phone crosses the geofence around your location address. The Presence Control Center sets the radius, which defaults to 150 meters. See Automatic Check-in via location [Mobile].
We suggest this detection method as a coverage gap-filler, and it should not be used as the only presence signal. Geolocation requires employees to install the Envoy mobile app and enable location permissions.
Geolocation privacy
The Envoy mobile app asks the device's operating system a single yes/no question: is this phone inside the geofence around the workplace? Envoy receives only that answer. Exact coordinates are never sent to or stored in Envoy's databases, and Envoy has no visibility into where a device is at any other time, including outside business hours, on weekends, or anywhere other than the location radius you've configured.
Layering signals for redundancy
You are not limited to one presence integration per location, and you don't have to use the same one everywhere. A campus with badge readers can run access control as its primary signal while a satellite office on a leased floor runs Wi-Fi and geolocation. Each signal at a location feeds into the same employee log, attendance reports, and emergency recipient lists.
Redundancy is the point. A badge reader outage, a laptop left at home, or a device that never joins Wi-Fi each creates a gap in one signal—and another covers it.
Automatic sign-out
Once you've established a reliable sign-in policy, the next step is to create an automatic sign-out process. These rely on the lack of signals, so it's best to create them once you can observe a few weeks of signal data.
Learn more about setting up automatic sign-out. Only global admins can access the Presence control center.
Adding context with HRIS
Presence integrations tell you who came in, but they can't tell you why someone didn't. Connecting your HRIS sends approved time-off data to Envoy, so an employee on PTO isn't counted as a missed day against your on-site policy. Time-off data syncs retroactively when you connect, so historical attendance reports improve immediately.
Managing and monitoring presence
Presence Control Center: Choose which signals Envoy accepts per location, set multi-signal requirements, configure automatic sign-out intervals and the geolocation radius. Available to global admins only.
Integrations Health Dashboard: Check that your presence integrations are actually sending data. A silently failed integration looks identical to an empty office.
Access log: This shows every signal Envoy receives, including ones you've turned off for check-in purposes. Useful for verifying a signal works before enabling it, while also allowing admins to see the flow of employees in and out of the building.









