Redirect on access denied
A space can now decide where to send a visitor who doesn't have access to a page — for example a public overview or a sign-up page — instead of showing a bare "Access denied". Set a redirect target on the space's access policy and anyone who lands on a page they can't read is taken there automatically. Spaces that don't set one are unchanged.