Owner role. Access can be granted via GCP’s IAM & Admin console.
The Cloud Resource Manager and Cloud Storage APIs must be enabled in the project. konduktor check gs enables them if they are off, which needs serviceusage.services.enable; if users don’t have it, have a project admin enable the APIs once: