Create, read, update, or delete Scorecards: Your API key must have the Edit Scorecards permission.
View Scorecards: Your API key must have the View Scorecards permission.
Approve or revoke Scorecard exemptions: Your API key must have the Configure Scorecard exemptions permission.
List Scorecard exemptions: API keys with the View Scorecard Exemptions permission see every exemption. A personal API key without that permission sees only exemptions its user requested in the Cortex UI; exemptions requested through the API are attributed to the API key, not the user.