What's new
- GB-Agent settings API: new
/api/settings/connectors/gb-agent/settingsroute lets workspace owners/admins read and update workspace availability, mode toggles, and access mode without accepting client-supplied workspace or user ids. - GB-Agent settings UI: Settings → Integrations → GB-Agent now exposes connector endpoint/token configuration, safe token status, workspace availability, draft-reply/draft-with-me/human-review mode flags, and all-members vs explicit allowlist access.
- Safe allowlists: the API caps allowlists, validates access modes and payload shape, and only persists current workspace member ids.
Notes
This release only adds settings/admin UI and API wiring. Runtime inbox gating remains intentionally deferred to the next GB-Agent enforcement slice.