Skip to content

Corporate travel · Per diem · Expenses

The system of record for every trip you approve.

Requests, approvals, passports and visas, per diem, and settlement, on one record that survives an audit. Running one company today. Tenancy across a whole portfolio, leave beside travel, and filing on behalf of someone else are approved design in build, and this page marks every one of them.

In buildmarks a capability that is designed and not yet deployed.

$1.71T

Global business travel spend forecast for 2026.

GBTA, 2026

48%

Of business travelers admit bending or breaking travel policy.

SAP Concur, 2026

80%

Of business travelers sometimes book off-platform.

State of Corporate Travel and Expense, 2026

If four in five trips are booked outside the tool, the record has to live somewhere the booking does not.

What breaks today

Three failures of the stack most groups are running.

01

The booking tool does not know who approved it.

Travel gets booked in one place, approved in a chat thread, and reconciled in a spreadsheet at quarter end. When Finance asks who signed off on the Riyadh trip, the answer is a search through messages.

02

Passports and visas expire quietly.

Nobody tracks document validity until someone is turned around at an airport. The traveler has uploaded the same passport to four systems and none of them raises a hand 60 days out.

03

Every company in the group needs its own everything.

One deployment per company means N systems, N admin consoles, and no way to answer a portfolio question. An executive working across two of them has two logins.

Multi-orgIn build

One deployment. Every company in the group.

This section describes approved design, not what Safar deploys today. The tenancy model is many-to-many: a person joins an organisation rather than belonging to one, and each membership carries its own reporting line, its own roles, and its own status. Writes will land in the organisation you have active. Reads will span every organisation you belong to, so a portfolio view becomes a screen rather than a spreadsheet built from four exports.

Membership
A different manager, role, and approval chain in each company.
Isolation
Postgres row-level security under the application filters, so a missing clause in a query cannot cross a company boundary.
Visibility
An org viewer role that reads every trip and leave record in a company, writes nothing, and manages nobody.
Calendars
Weekend days set per organisation, because Saudi runs Friday and Saturday while the UAE runs Saturday and Sunday, and leave duration is wrong in one of them otherwise.
One personFour memberships

L. Haddad

one login

Noon HoldingAdmin
Sivvi RetailApprover
Namshi LogisticsOrg viewer
Food Hall KSATraveler
Writes
Land in the organisation you have active.
Reads
Span all four, so "who is out next week" is one screen.

Platform

Six things a booking tool leaves to a spreadsheet.

Trips with a real lifecycle

Ten states from draft to closed, with multi-leg itineraries, routine patterns for recurring travel, and cancellation that keeps the record. Date-driven jobs move trips between states without anyone pressing a button.

draft → submitted → approved → ready → in progress → completed → closed

Approvals that route themselves

Requests follow the approver matrix with an admin fallback when the chain breaks. Re-approval triggers on a destination change or a date shift over three days. Delegation is date-ranged, so cover is arranged before the leave starts.

One reminder at 48 hours. No escalation ladder.

Documents that raise their own hand

Passports and per-leg visas live in one vault, uploaded once and reused across trips. Safar computes travel readiness per leg and warns on expiry rather than waiting to be asked.

Camera capture · encrypted offline reads · on-device passport recognition

Expenses that survive an audit

Every foreign-currency line stores an immutable rate snapshot at the transaction date with its source named. Per diem replays against policy with meal-provision deductions, and a missing receipt is allowed with a written declaration.

Money is integer minor units. No floating point on the money path.

In build

Leave beside travel, not in another tab

Allocation, request, approval, and balance, in the product that already knows who is where. Duration counts against your own weekend days and your country's public holidays.

Safar is the system of record, not an accrual engine.

In build

Logging on behalf of someone else

An executive assistant files travel, leave, and expenses for the person they support. Every proxied write records who acted and who it was for, and both show in the audit trail.

The grant is wide. The transparency is what makes it safe.

Trip lifecycle

Ten states, and one of them is the trip nobody asked about.

  1. 01

    Draft

  2. 02

    Submitted

  3. 03

    Approved

  4. 04

    Ready to travel

  5. 05

    In progress

  6. 06

    Completed

  7. 07

    Expenses due

  8. 08

    Expenses submitted

  9. 09

    Closed

  10. 10

    Cancelled

Scroll →

Retro-approval covers the trip somebody took without asking. It blocks the finance export, not the submission.

Four roles

Everybody sees the part of it that is their job.

Traveler

Files a request, uploads a passport once, logs expenses on a phone with no signal, and gets told when a visa is close to expiring.

Approver

A queue with the trip, the traveler, and the reason. Approve or return for changes. Arrange cover before you travel.

Admin

Per-diem rules, travelers and roles, the offboarding queue, the audit trail, and the finance export.

Org viewerIn build

Reads every trip and leave record in the company. Writes nothing. Manages nobody.

Security and data

Six controls, and the two that are not running yet.

Google Workspace only

Sign-in is domain-gated and invite-only. There is no password to leak, and this landing page is the only thing Safar answers without a session.

Row-level security in the databaseIn build

Isolation between companies is a Postgres policy rather than a filter somebody remembered to write.

Least-privilege database roles

The web process connects as a restricted role that cannot reach what the worker can.

Documents behind short-lived links

Uploads are size- and type-bounded, and every access is written to an append-only log.

Retention you configure

Purge windows for personal files, and a longer clock for financial records, are configurable per organisation. The purge itself stays switched off until your HR and Legal teams sign the windows off.

Logs that redact themselves

The logger strips emails, tokens, signed URLs, and passport lines by key and by value shape.

Questions

The ones that decide it, answered first.

See it against your own travel policy.

Thirty minutes, your org chart, your destinations, your per-diem rates.

Book a walkthrough