vSphere with Tanzu provides a sample role, Workload Storage Manager, that includes a set of privileges for storage operations. You can clone this role to create a similar role.
|Privilege Name||Description||Required On|
|Allows storage administrator to see the Cloud Native Storage UI.||Root vCenter Server|
|Allows allocating space on a datastore for a virtual machine, snapshot, clone, or virtual disk.
Allows performing read, write, delete, and rename operations in the datastore browser.
|Shared datastore where persistent volumes reside|
|Allows modifications to an agent virtual machine such as powering off or deleting the virtual machine.||vSphere Pod|
|Allows assignment of a virtual machine to a resource pool.||Resource pools|
|Allows viewing of defined storage policies.||Root vCenter Server|
|Allows creation and deletion of virtual machines. Allows configuration of virtual machine options and devices.||vSphere Pod|