Put MailSentry's answer on the page where the question is asked. Every surface below is a read-only widget another product — Clarity first — renders inline on its own control page. The tenant comes from the shared sign-in, never from the embedding page, so a control page can only ever show its own organisation's posture.
This is the real widget against the real endpoint with your own account — not a mock. Whatever it shows here is what the embedding product's users will see.
EMBED_FRAME_ANCESTORS; without it the widget is same-origin only.SameSite=None.data/clarity-control-map.json. Until then the widget renders its "not linked" state — by design, no error.