API Access has one form now: who will use the token (a new AI agent or an existing member) and what it may do. Five groups: Reader (only reads), Writer (finds content, drafts, submits to Review), Reviewer (grades what waits in Review), Publisher (writes, reviews and approves) and Full access. A token outside its group gets a clear 403 naming the permission it lacks, and GET /account shows the token its own group. Tokens created before keep full access.