Hi FIXED-TERM Ciui Bianca-Laura (XC-DX/EXV-T-RO) - Thanks for reaching out.
Based on the above you shared, that is the definition for the custom role being created i.e. it will allow the action for defined management plane (list keys) versus data plane (reading of blobs).
However, this ideally won't help in controlling the SAS permissions.
While generating the SAS, the permissions need to be supplied and therein you can do that same i.e. Read, List etc as per your requirement.
I'll take another review once though but as of now, the above seem to be correct.
Hope that helps!
Let me know if there are any queries/concerns, will be glad to assist.
Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.