push.tt runs on a data connection, so the moment it is most likely to fail is the moment somebody crosses a border. A built-in eSIM store closes that gap without a shop, a SIM tray, or a roaming bill nobody approved.
Every other feature on this site assumes a connection. For a crew that stays in one city that assumption is safe, and for a crew that crosses borders it is the single thing most likely to take them off the air.
Choose a data plan in the Android app or management console, pay from the organisation's prepaid wallet, and assign it to the person who needs it.
An eSIM is a data pipe. It sits underneath push.tt in exactly the same place your home Wi-Fi does, and it changes nothing about who can read your traffic.
The honest cost: buying anything means a payment processor and an eSIM provider learn that a purchase happened, for which destination, and when. That is new metadata leaving your organisation, it is unavoidable in any store, and it will be listed in the security model rather than left for you to work out.
These decide whether an eSIM is useful for a particular trip or handset, and none of them are things an app can engineer away.
Choose the plan centrally, assign it to the traveller, and let the handset handle the installation route it supports.