A service token is not end-user authorization
A service-to-service token proves which machine called your API. It does not prove which human may see or change a specific resource.
If an internal worker calls GET /invoices/4821 with a service JWT, that only authenticates the worker. Still authorize the end-user context (or the job’s declared principal) for that invoice: actor, tenant, object, and action.
Otherwise every service credential becomes a master key to every tenant’s data.
