Before You Begin
Creating a workspace writes to two systems: it creates the workspace in Next-Gen Trust Security and the matching IAM scope in the platform. Each side has its own permission. The Workspaces permission set authorizes the Next-Gen Trust Security side, and the IAM administrator role authorizes creating the scope in the platform. A user needs both to create a workspace.
You can add the Workspaces permission set to a custom role, so managing workspaces does not require making someone a full Next-Gen Trust Security administrator, though they still need the IAM administrator role.
Choose the name with some care, though you are not stuck with it. You can rename a workspace later, but its scope name is fixed at creation and is never regenerated, so a renamed workspace and its scope stop resembling each other.