Permissions for @turbot/azure-iam

Taking a look at permissions and associated grant levels for each permission for IAM:

PermissionGrant LevelHelp
microsoft.authorization/classicadministrators/readMetadataget administrator
microsoft.authorization/classicadministrators/writeOwnerset administrator
microsoft.authorization/classicadministrators/deleteOwnerdelete administrator
microsoft.authorization/roleassignments/readMetadataget role assignment
microsoft.authorization/roleassignments/writeOwnercreate role assignment
microsoft.authorization/roleassignments/deleteOwnerdelete role assignment
microsoft.authorization/permissions/readMetadatalist permissions
microsoft.authorization/locks/readMetadataget management locks
microsoft.authorization/locks/writeOwneradd management locks
microsoft.authorization/locks/deleteOwnerdelete management locks
microsoft.authorization/roledefinitions/readMetadataget role definition
microsoft.authorization/roledefinitions/writeOwnercreate or update custom role definition
microsoft.authorization/roledefinitions/deleteOwnerdelete custom role definition
microsoft.authorization/provideroperations/readMetadataget operations for resource providers
microsoft.authorization/policysetdefinitions/readMetadataget policy set definition
microsoft.authorization/policysetdefinitions/writeOwnercreate policy set definition
microsoft.authorization/policysetdefinitions/deleteOwnerdelete policy set definition
microsoft.authorization/policydefinitions/readMetadataget policy definition
microsoft.authorization/policydefinitions/writeOwnercreate policy definition
microsoft.authorization/policydefinitions/deleteOwnerdelete policy definition
microsoft.authorization/policyassignments/readMetadataget policy assignment
microsoft.authorization/policyassignments/writeOwnercreate policy assignment
microsoft.authorization/policyassignments/deleteOwnerdelete policy assignment
microsoft.authorization/operations/readMetadataget operations
microsoft.authorization/classicadministrators/operationstatuses/readMetadataget administrator operation statuses
microsoft.authorization/denyassignments/readMetadataget deny assignment
microsoft.authorization/denyassignments/writeOwnercreate deny assignment
microsoft.authorization/denyassignments/deleteOwnerdelete deny assignment
microsoft.authorization/policies/audit/actionOwner'audit' policy action.
microsoft.authorization/policies/auditifnotexists/actionOwner'auditifnotexists' policy action.
microsoft.authorization/policies/deny/actionOwner'deny' policy action.
microsoft.authorization/policies/deployifnotexists/actionOwner'deployifnotexists' policy action.
microsoft.authorization/elevateaccess/actionOwnerassigns the caller to user access administrator role