I tried to set this up myself on PVE 8.0.4 with user@pam
The Pool.Audit permission is required to select the resource pool.
For the user, to view its own permissions, the Sys.Audit permission would be required. In my tests, I was unable to see it.
To clone a VM i also needed the SDN.Use...