I may be using the wrong terminollogy here, but so far as I can see there's certain CF products which require their own tokens to be set up. Others, however, require account-level tokens that cover those permissions.
What's a good way to understand the split here?