Users roles are not very granular, if an admin only has read only network access then they cannot make changes on SM. As suggested the best option is to have SM in it's own network.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.