What I think you're missing is the possibility of using these tokens as an attack vector in this case - social engineering. Impersonating a senior manager or a C level entity.
So while on the surface you can say that the risk is minimal this can be damaging to a business provided you impersonate the "right" person.