Permissions for AD Cleanup Tool

Is there a list of permissions for accessing the ADUC Cleanup Tool? One of our support groups gets ’ Insufficient Recast Permissions’ when trying to access it.
They currently have
Active Directory - Add or Remove Account from Group

Hey there,

We don’t have a specific template for the AD cleanup tool, but it may be helpful to start by assigning them our custom read only role to grant them all of the required permissions to view everything in the dashboard and then assign additional permissions as needed if for example you want them to be able to delete devices from Config Mgr or AD.

This will walk you through setting up the role Assign a Read Only Access Role | Recast Docs (