GET api/team-members/me/permissions returns the keys the signed-in user holds after role defaults and their own overrides, evaluated by the same policy that guards writes. The user comes from the token; a missing or unknown identity gets 401.