Read and act on the same records people use.
API credentials are issued per app and environment, scoped to what the app needs, and governed by the organization's roles and authority policies. An API call cannot do what the policy would not let a person do.