🔑 Password Recovery
New admin action under Security: pick a user, pick which of their connected apps need a password reset, and generate a recovery link per app from one wizard. Links are emailed to the user, who completes the reset themselves via a verified, app-scoped link — no shared credentials, no manual "reset your Slack password" ticket. Failed link generation can be retried inline. Alongside it, Workflows gained two new Leaver steps: Remove from All Groups and Remove from All External Platforms, for cleaner automated offboarding.
🛡️ MFA Status, Everywhere
User list, external-profiles list, and the apps widget now all show an MFA status indicator per connected account — enabled, disabled, or unknown. Previously an unknown state showed as "disabled," which was misleading. Renamed from "2FA" to "MFA" since the signal reflects registered strong-auth methods, not literally two factors.
⚡ Faster, Smarter Search
The users table now filters, sorts, and paginates on large orgs without slowing down. The command palette (Cmd/Ctrl+K) grew three new action types: type "switch" to jump between organizations (role shown per org), "dark"/"light"/"theme" to toggle appearance, or a language name to switch locale. Recent searches are now scoped per-org so they don't leak across an account switch.
🛠️ Fixes & Stability
Orphaned-accounts reporting is more accurate — active counts and acknowledged accounts now reflect reality, and stale entries from deleted users get cleaned up automatically.
Cross-org group membership leak closed; group member list fixed when empty; date-format and popover display fixes across a few screens.















