- Introduces Organization-to-Application Entitlement, enabling per‑org control of app access without custom code
- Entitlement enforcement is opt‑in and disabled by default, allowing safe configuration before activation
- Login attempts to apps a member isn’t entitled to are automatically denied when enforcement is enabled