The permissions a new member starts with.
GET /users/defaults — returns the dashboard-configured starting
permission set used to seed the new-user invite form. Gated on
users:create so an invite-capable operator who lacks settings:read
can still load the form without going through the locked /settings
surface. If the configured set has since been deleted, permissions comes
back empty rather than failing, so the form still opens.
Authorizations
A scoped AgentEye API key. Mint one in the dashboard under Settings → API keys, or with POST /v1/keys. Each endpoint names the permission it requires; a key without it gets 403 and a required_permission field naming what was missing.
Response
The default permission_set and the permissions it resolves to.

