Index: src/services/ap-inbox.js
===================================================================
--- src/services/ap-inbox.js	(revision d8c50422e2c6dcfc2230efcb5dabb4518bcb1913)
+++ src/services/ap-inbox.js	(revision 31680c3360308110ee32435ada564ef21f612bce)
@@ -29,4 +29,5 @@
 import { parsePoll, recordPollBallot } from './ap-polls.js';
 import { fwStmts } from './ap-following.js';
+import * as HubInvite from './hub-invite.js';
 
 /**
@@ -559,5 +560,10 @@
     // Wards vallen hier nooit: de guardianpoort hierboven gaat vóór.
     const ownerGate = db.prepare('SELECT approve_followers FROM sites WHERE slug = ?').get(slug);
-    if (ownerGate && ownerGate.approve_followers) {
+    // Behalve als de eigenaar dat ja al gaf: [Add to HUB] op /connect geldt
+    // een dag als toestemming voor een Follow van de hub. Alleen als de hub
+    // hem ZELF ondertekende. Zie services/hub-invite.js.
+    const alGoedgekeurd = !!(verified && verified.id === who && HubInvite.isInvited(slug, who));
+    if (alGoedgekeurd) console.log('[AP] Follow', who, '→', slug, '(pre-approved via Add to HUB)');
+    if (ownerGate && ownerGate.approve_followers && !alGoedgekeurd) {
       const followId = (typeof act.id === 'string' && act.id) || `${who}#follow-${Date.now()}-${rid()}`;
       Guardianship.follows.recordPending(slug, {
