I believe my question is a level below.
Network admin or org admin don't really matter, it is the same org/admin api call. If you give a network full access to a user from the org/admin api call, you will see that user as a network admin in the network/admin gui.
The component that allows to give port privileges policy based on tag to a user is what I am looking for here.
( this : https://www.dropbox.com/s/eeayhednpcemfuj/Screenshot%202020-07-21%2009.15.49.png?dl=0 )
Same issue with the saml Roles, it needs the port management privileges bit.