- Added self‑service configuration for third‑party app access and Cross‑App Access (XAA) via the My Organization API and embeddable UI components (early access).
- Organization admins can now independently manage third‑party app access at the organization and connection level, and assign XAA resource application roles, with guardrails set by the tenant.
- XAA requires the connection’s identity provider domain to be verified for the organization, ensuring cross‑app authorization is scoped to trusted providers.