| Email backend | NAVIGATOR_EMAIL_BACKEND | Must be sendgrid outside the harness |
| Outbound SendGrid | SENDGRID_API_KEY, SENDGRID_FROM_EMAIL | Required outside the harness |
| SendGrid base URL | SENDGRID_BASE_URL | Official hosts only outside the harness |
| Inbound URL gate | SENDGRID_INBOUND_SECRET | Required outside the harness |
| Inbound signature | SENDGRID_INBOUND_PUBLIC_KEY | Required when summary review is enabled |
| Attachment scanner | NAVIGATOR_CLAMD_ADDR | Required in every deployed profile; private clamd only |
| Event webhook | SENDGRID_EVENTS_SECRET, SENDGRID_EVENTS_PUBLIC_KEY | Required outside the harness |
| Threaded mail | NAVIGATOR_PARSE_HOST, NAVIGATOR_LAWYER_NOTIFY_EMAIL | Both values enable it |
| Summary opt-in | NAVIGATOR_SUMMARY_ENABLED | Enables durable review |
| Summary identity | NAVIGATOR_DEPLOYMENT_ID, NAVIGATOR_SUMMARY_CHANNEL_ID | Durable review coordinates |
| Summary envelope | NAVIGATOR_SUMMARY_ENVELOPE_RECIPIENTS | Unset/off by default; blank values fail |
| SMS intake | NAVIGATOR_SMS_NUMBER, TWILIO_AUTH_TOKEN | Off by default; a number needs the token |
| Summary Gemini model | NAVIGATOR_SUMMARY_GEMINI_MODEL | Optional Vertex model override |
| Summary Gemini location | NAVIGATOR_SUMMARY_GEMINI_LOCATION | Optional Vertex location override |
| Summary input limit | NAVIGATOR_SUMMARY_MAX_INPUT_CHARS | Optional input limit |
| Summary output limit | NAVIGATOR_SUMMARY_MAX_OUTPUT_TOKENS | Optional output limit |
| DKIM fence | NAVIGATOR_DKIM_REQUIRE_DOMAIN | Optional domain pin |
| Lawyer-sender DKIM check | none (always on) | Must pass for sender's own domain on every lawyer command/relay |
| Internal ops notices | SLACK_WEBHOOK_URL | Optional; otherwise captured in memory |
| Per-Project client-view notices | SLACK_BOT_TOKEN | Required outside the harness; creates private Project channels |
| Dash0 endpoint | DASH0_ENDPOINT | Optional staging-only integration declaration |
| Dash0 dataset | DASH0_DATASET | Required with DASH0_ENDPOINT |
| Dash0 token | DASH0_TOKEN | Encrypted Secret Manager input; required with DASH0_ENDPOINT |
| DocuSign endpoint | DOCUSIGN_BASE_URL | Declares DocuSign; demo in dev, live in production |
| DocuSign account | DOCUSIGN_ACCOUNT_ID | Environment-specific account |
| DocuSign JWT IDs | DOCUSIGN_INTEGRATION_KEY, DOCUSIGN_USER_ID | Preferred auth path |
| DocuSign JWT proof | DOCUSIGN_PRIVATE_KEY, DOCUSIGN_OAUTH_BASE | Preferred auth path |
| DocuSign static auth | DOCUSIGN_ACCESS_TOKEN | Short-lived fallback |
| DocuSign signer | DOCUSIGN_SIGNER_EMAIL, DOCUSIGN_SIGNER_NAME | Required signer identity |
| DocuSign webhook | DOCUSIGN_HMAC_KEY, DOCUSIGN_WEBHOOK_SECRET | Required once DOCUSIGN_BASE_URL is set |
| Xero tenant | XERO_TENANT_ID, XERO_BASE_URL | All Xero values select real billing |
| Xero OAuth client | XERO_CLIENT_ID, XERO_CLIENT_SECRET | Otherwise stub billing |
| Xero OAuth token | XERO_TOKEN_URL, XERO_SCOPE, XERO_ACCESS_TOKEN | Otherwise stub billing |