Before You Begin
Creating a workspace writes to two systems: it creates the workspace in Next-Gen Trust Security and the matching IAM scope in the platform. The Workspaces permission set covers both, so a role that has it needs nothing added.
The permission set is available to custom roles, so you can grant workspace administration to a team without making them Next-Gen Trust Security administrators.
Choose the name with some care, though you are not stuck with it. You can rename a workspace later, but its scope name is fixed at creation and is never regenerated, so a renamed workspace and its scope stop resembling each other.