SSO getting user permissions in token if user logs in to different client

I’m trying to figure out how to get a user’s roles and permissions for a client application if when they logged in it was for a different client/application (we have created multiple applications in Auth0 but they share an API so that we can have SSO across our apps).

At the moment the roles and permissions custom claims are only included for the client/application that the user was authenticated against and I don’t want them to have to keep authenticating as they switch apps.