navan-security-basics
Installation
SKILL.md
Navan Integration Security Boundary
Overview
Threat-model a Navan integration across identity, travel, expense, payment, file, and downstream systems. This workflow produces an auditable decision or artifact before any live action.
Prerequisites
- Access to the selected tenant's current Navan Help Center and contracted integration documentation.
- A named business owner and data owner for the travel or expense workflow.
- A non-production evidence set with secrets and traveler data removed.
Current Contract
Navan states that its APIs undergo security testing and that data in transit and sensitive data at rest are encrypted. Those vendor controls do not replace customer-side least privilege, downstream encryption, retention, monitoring, or third-party AI governance.
Authentication
Use dedicated integration identities, scoped access, approved secret storage, host binding, rotation, and revocation. Keep interactive admin and automation credentials separate.