Google Pane
Workspace state, read live from workspace_account + v_mail_one_pane — never a credential value. Grouped by domain. This is the Workspace pane; onepane.html is a separate iframe surface left as-is (still linked elsewhere in the portal).
DWD grant (apps_script_toggle) is refreshed by every roster run and is live as of the timestamp below. The Apps Script switch (apps_script_api_user_setting) is a separate, point-in-time probe — the roster refresh (probe_workspace_accounts.mjs --write) does not re-test it, so it is always shown as "last probed <time>", never as current state. Confirmed stale on 2026-09-20: three accounts read BLOCKED_403 as of a 14:57 probe while a later read-only check found them ENABLED.
Reachability by surface
Per domain and surface (Gmail, Drive, Calendar, Tasks, Docs, Sheets, Slides, Apps Script): reachable or not over domain-wide delegation as proved by a probe — the timestamp is the probe's, never this page's render time, and a blocked cell shows Google's verbatim error. Source control_capability via _ops/scripts/google-pane-probe.mjs (daily, com.brg.google-pane-probe). Key names only, never values.
Loading…
By domain
Loading…