you need to set the action for the policy to Service Token rather than Allow
you need to set the action for the policy to Service Token rather than Allow
Zone Settings = Edit?Account:Email Routing:EditZone:Email Routing Rules:Edit



Zone.Zone Settings: Read to read it, but then a completely different permission to write... Zone.Zone: Edit. Not even sure what Zone.Zone means considering there's already a different Zone.Zone Settings permission.ParentRayID which points you to the request that triggered it
"WorkerCPUTime": 0,
"WorkerStatus": "unknown",
"WorkerSubrequest": true,
"WorkerSubrequestCount": 0,
"WorkerWallTimeUs": 0,ParentRayID