403 Forbidden on Compliance Recording API via CLI in AU-1 BYOC

Trying to make sense of why the CLI returns 403 Forbidden when fetching compliance recording metadata via the /api/v2/analytics/conversations/recordings endpoint. Using Genesys Cloud CLI v2.1.0 in AU-1 BYOC. Service account has Admin:Analytics and Admin:ComplianceRecording permissions. Direct API call works with same token. Pipeline fails at the fetch stage for audit logging. Any known scope issues with CLI v2.1.0 for these endpoints?