Introducing dedicated actions for stack dependency management would be a solution for this, such as:
STACK_DEPENDENCY_CREATE
STACK_DEPENDENCY_DELETE
These could follow the same pattern as existing stack-scoped permissions (e.g. STACK_SCHEDULED_RUN_CREATE), allowing them to be included in custom roles without requiring full admin access.