* feat(custom-block): deploy a workflow as a reusable org-scoped block
* fix(custom-block): reseed deploy form, guard duplicate publish, run child deployed
* test(custom-block): isolate custom-block rows fetch in execution-core test
* fix(custom-block): allow cross-workspace exec, org-scope authority, keep field ids, hide disabled
* feat(custom-block): run child under source owner's identity, workspace, and env
* fix(custom-block): bind publish authz to the source workflow's workspace
* fix(custom-block): gate edit/delete on source-workspace admin, not org admin
* chore(custom-block): rebaseline route count to 887 after staging merge
* fix(custom-block): sanitize failure output so it can't leak source workflow internals
* fix(custom-block): derive inputs and curated outputs from deployed state, not draft
* fix(custom-block): hide disabled blocks from the toolbar palette too
* fix(custom-block): bill nested + failed-run hosted cost; expose real inputs to the agent
* fix(custom-block): enforce enterprise + flag gate at every consumption path