What Coupa AI and Coupa Navi agents can do with money in 2026
Coupa Navi is the brand for Coupa's AI agents. Coupa released its first Navi agents in May 2025, and by its 20 August 2026 release it said more than 450 customers ran Coupa agents in production, with over 50 specialized agents across early access, limited availability and general availability. The September release made three more agents generally available, including an Invoice Attachment Validation Agent that automates approve and reject decisions on invoices.
The agent that matters most for a controller is the Navi Payment Batch Creation Agent. Coupa reports that in five weeks in production it autonomously ran 14 payment batches covering 2,395 payments worth 20.1 million dollars, at roughly 27 dollars in AI credits. That is a real result, and it is also the clearest statement in the industry that agents now sit inside the payment run, not beside it.
Customers build their own agents too. Navi Agent Studio went generally available in May 2026 as a no-code builder with role-based access to agents, and Coupa says more than 400 custom agents were built in its first months, making it the most used AI feature on the platform.
Coupa MCP and Navi Connect for outside agents
The Coupa MCP integration ships as part of Navi Connect. Coupa announced it at Inspire in May 2026 with third-party integration, MCP and agent-to-agent support expected in September, and the 20 August release confirmed it: external AI including Microsoft Copilot and custom-built agents can use more than 30 out-of-the-box tools across procurement, invoicing, contracts and expenses. Coupa's own wording is that access is auditable and read-write and inherits each user's existing permissions and security controls.
That sentence is the whole governance model, so we checked what it means at the protocol level. Read-write is the default, not an upgrade, and the permission boundary is the human who signs in. There is no per-agent identity with its own limits in the token.
How we measured the Coupa MCP authorization server
Coupa runs a separate instance for every customer at <tenant>.coupahost.com. There is no central MCP host: mcp.coupa.com does not resolve. So on 5 October 2026 we took six US enterprise and university tenants whose Coupa addresses are printed in their own public supplier guides and sent each one the same unauthenticated requests. We do not name the customers here. Anyone can repeat the test against their own tenant.
For every tenant we fetched the OpenID configuration, the MCP protected-resource document, the MCP authorization-server document, and sent a JSON-RPC initialize to /mcp. As a control we requested a randomly generated path on each host and a random suffix under the protected-resource path. Every control returned 404 on all six, so nothing below is a catch-all server answering 200 to anything.
Five tenants had MCP live. Each returned a protected-resource document naming /mcp as the resource and /mcp-auth as its authorization server, and answered the initialize call with 401 and a spec-correct WWW-Authenticate: Bearer challenge pointing back at that document. The sixth returned 404 on every MCP path, which tells you MCP is switched on per tenant rather than everywhere at once.
Two MCP scopes against 314 API scopes
The MCP authorization server on all five live tenants publishes exactly two scopes, t:read and t:write, and its metadata sets default_scopes to both. It supports only the authorization-code grant with PKCE S256, accepts public clients with no client secret, and advertises a dynamic client registration endpoint. We did not register a client on anyone's tenant. The metadata alone settles the question.
Compare that with the main Coupa OAuth server on the same hosts. It publishes 314 scopes, identical on all six tenants, and they are precise: core.approval.write approves, rejects and holds approvals, core.invoice.approval.write adds and removes invoice approvers and restarts approvals, core.budget.write creates and adjusts budget lines, and there is a scope literally named core.invoice.approval.bypass. 155 of the 314 grant more than read access, and 57 of those touch invoices, payables, payments, cards, budgets, approvals or treasury.
An integration built on the core API can be given three of those scopes. An assistant connected through Coupa MCP is offered read and write. The granularity Coupa built for integrations does not reach the MCP consent screen, so the only thing that narrows an MCP agent is the role of the person who connected it.
Where the dollar limit sits for a Coupa agent
Coupa deserves credit here. It is the strongest platform in our series on structured approvals. Approval chains can route by amount, approvers can carry approval limits, budgets can block or warn, and invoice tolerances catch price and quantity drift. Those are real ceilings, and you should configure them before any agent goes live.
They are ceilings on people and documents. Not one of the 314 scope names, and neither of the two MCP scopes, carries an amount, limit or threshold. When a controller with a 250,000 dollar approval limit connects Copilot through MCP, the assistant inherits that 250,000 dollar authority. It has no budget of its own, no lower per-transaction cap, and no monthly total that stops it. The audit log records what happened, which is valuable after the fact and does nothing to stop the next approval.
Payments need a precise reading too. Through the core API, core.pay.payments.write only marks payments as exported. It cannot originate a payment. Coupa's own agents are a different case: the Payment Batch Creation Agent builds the batches itself, inside Coupa, governed by whatever approval and payment controls the customer configured for the payment run.
A rollout checklist for Coupa AI agents that touch spend
- Connect Coupa MCP as a dedicated, low-authority user. The token will be read and write whatever you do, so the role is your only lever. Never connect as a controller, AP manager or anyone with treasury access.
- Set approval limits on that user in the approval chain. Treat the agent as an approver with the smallest limit that still lets it do its job, and send everything above it to a named person.
- Keep invoice tolerances and budget checks strict. They are the controls that still fire when the actor is an agent.
- Audit the integrations holding
core.approval.write,core.budget.writeorcore.invoice.approval.bypass. These are the scopes that let software change who approves and how much is available. - Put agent purchases that leave Coupa behind a payment layer with a per-agent budget. Cards, API spend and checkout purchases an agent makes outside your procure-to-pay flow are not covered by a Coupa approval chain at all.
How AgentsPay fits alongside Coupa
AgentsPay does not replace Coupa. Keep Coupa as the system of record for requisitions, purchase orders, invoices and payment runs. AgentsPay governs the agent: each agent gets its own wallet and identity, a hard per-agent spend limit, a per-transaction ceiling, an approval threshold that pauses for a human, and scoped virtual cards for anything it buys outside the procure-to-pay flow. Every decision lands in an audit trail you can reconcile against Coupa.
If you are pricing the Coupa side of that stack, our Coupa pricing breakdown covers what Coupa publishes and how Navi AI is billed. For the wider procurement picture see AI procurement software and agentic procurement and our procurement agents use case. The same measurement on SAP is in SAP Joule agents