- Organizations can now allow or block third‑party app access on a per‑organization basis, with access blocked by default for existing orgs.
- Third‑party app connections must be promoted to domain level (is_domain_connection:true) to authenticate users within an organization.
- User consent is scoped per organization, so granting access in one organization does not carry over to another.