Basically what this page suggests:
Auth0’s actions provide access to an
authorizationobject on theevent, which is documented to contain therolesassigned to the user. However, I need access to the permissions associated with the roles without using the API Management client.