In the latest SmarterTrack release (9553) there is a new whitelist for agents, admins, and API. While this is a good idea in general, in practice there should be 3 separate whitelists, rather than all three grouped together. API whitelists should be extremely narrow, while agents and admins are potentially located in completely different places.
The way it stands now, with all three categories sharing the same whitelist, having a huge agent support team whitelisted would expose the API and admin interfaces to too large of an attack surface.
At the very least, the API should have its own whitelist, but the best-case scenario is three separate lists.