Navan Event Delivery Contract Verification
Overview
Validate and operate the event or change-delivery mechanism actually enabled for a Navan tenant. This workflow produces an auditable decision or artifact before any live action.
Prerequisites
- Access to the selected tenant's current Navan Help Center and contracted integration documentation.
- A named business owner and data owner for the travel or expense workflow.
- A non-production evidence set with secrets and traveler data removed.
Current Contract
Navan's public pages confirm APIs, SFTP, and direct integrations but do not establish a universal webhook endpoint, event taxonomy, or signature header. Use only the tenant's documented delivery mode and keep polling or reconciliation as a recovery path.
Authentication
For callbacks, use the documented verification scheme and secret lifecycle; for polling or files, use the corresponding read-only identity. Never invent a generic vendor-signature header.
Instructions
- Confirm whether the tenant surface supports callback, poll, file, or managed delivery.
- Capture event or record identifiers, ordering, duplication, correction, and replay semantics.
- Authenticate before parsing and enforce body or file size limits.
- Journal receipt before acknowledgement and deduplicate durably.
- Process idempotently with quarantine for unknown types or schemas.
- Reconcile periodically against the source-of-record contract.
Tool Discipline
Use Read, Glob, and Grep to inspect documentation, schemas, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Invocation alone does not authorize network access, credentials, traveler or expense data, bookings, payments, policy or identity changes, file transfers, deployments, or deletion.
Approval Boundaries
Registering destinations, issuing verification secrets, enabling new event classes, replaying deliveries, or applying state changes requires explicit approval.
Error Handling
- A fast acknowledgement must not precede durable receipt.
- Unknown events go to quarantine, not the default handler.
- A delivery gap requires source reconciliation, not blind replay.
Output
Return delivery-mode evidence, authentication, ordering model, dedupe key, acknowledgement rule, reconciliation cadence, and replay approvals. Identify assumptions, owners, expirations, and evidence gaps explicitly.
Examples
- Choose polling because no callback contract is enabled.
- Reconcile a managed accounting integration after a delivery gap.
Validation
Test invalid authentication, duplicate, out-of-order, unknown schema, crash before acknowledgement, replay, and gap recovery. Record expected and observed results, including fail-closed behavior.
Resources
- Current first-party evidence map — recheck dated sources and the selected tenant's in-account contract before relying on mutable endpoints, fields, entitlements, limits, or delivery behavior.
- Record tenant observations as environment-specific evidence, never universal Navan guarantees.