customer:read · customer:balance:write · ceiling viewCustomers
customerKey is the base64url encoding of the lowercase email (the key field on list rows).
Balance body:
type is add, subtract, or set. Path storeId wins over any body storeId.