No, I can't provide you with such a list, just want to do some remarks.
You have to understand the differences...
at the resource group level, you administer the services in Azure itself, who can deploy services in that rg, who can manage those deployed services, make changes to the service configuration, and who is allowed to deploy a new SQL server (eventually cost impact)
at the service level (kv, SQL server...), you are setting up security IN the service itself, e.g., in a key vault... who is allowed to create secrets, who are allowed only to read secrets or on a SQL server... who is allowed to create new databases, you can create new users and set roles for those new users.
So you will find many services in Azure where you have to make this "two-level security approach."