Need to define RBAC based on the audit log. This can be a regular process to onboard a team and provide access.
I find audit2rbac tool simple and clear to use.
Need guidance wrt kubernetes service on azure.
The control plane log streams (including the audit log) are available through Azure diagnostic logs. See here: