The short version
Flowmails does not own a mail server. It does not run its own database. It does not even host the worker that processes your inbound mail. Every one of those pieces is provisioned on your Cloudflare account, using your token, on your behalf. The permission list reflects that: it is the union of everything the platform has to be allowed to touch while bringing a fresh domain online and keeping it that way.
Cloudflare's API token model is now organised into two scopes — All domains and Entire account — each broken into a handful of sub-scopes that group related permissions. There is no “Operator” preset that maps cleanly onto what Flowmails needs, so the walkthrough below is the smallest set we have been able to land on after a few rounds of trimming, grouped the same way the new token page groups them.