There is no need of IAM roles on Storage account. Just giving the permisions to workspace and then to table level to your group will do the job