My sugestion is that you make a good intial work regarding how you like to divide the access right
My recomendation is that you create roles for each type of situation you like to combine
Example roles can be
Environmental access roles;
PROD -> access to producvtion environments
TEST -> access to development environments
DEV -> access to development environment
Functional Roles;
Deployer -> able to run deployment processes
Operator -> able to stop/start
Functional administrative roles;
Administrator
Proces developer