Added Added new API GET /v1/campaigns/{campaign_id} endpoint to fetch a single access review campaign by ID Added query filters to GET /v1/campaigns supporting filtering by name, status, and created/started/ended/stopped time ranges Improved Read-only Opal API tokens can no longer invoke state-changing tools through the MCP endpoints; such calls are now rejected, matching the read-only enforcement already applied to the REST and GraphQL APIs Admins can now see which delegations are gated by an OpalScript delegation condition directly from the script console The admin access-campaign page now l