Per-workspace connections and access tokens
Connections are now workspace-aware. A connected account is visible only to the workspace that connected it by default, so a personal integration does not silently leak into a shared workspace.
What changed
- Per-workspace visibility, with an organization policy to set the default.
- A one-click grant to extend a connection to another workspace when you do want to share it.
- An audit log foundation so admins can see how connections are used.
Personal access tokens moved to organization settings and are pinned to a workspace at the moment they are issued, so a token's reach is clear from the start.