Users of the log_administrators role have all user permissions and additionally can:
To create and drop triggers, users must also have such permissions in the target schema.
To clear logs, users must also have UPDATE permissions on the captured tables.
You can find log_administrators permissions in the logs.usp_set_role_permissions_administrators procedure.
Users of the log_users role can:
To select log records, users must also have SELECT permissions on the captured tables.
To restore records, the user must also have UPDATE permissions on the captured tables.
You can find log_users permissions in the logs.usp_set_role_permissions_users procedure.
You can use the sp_addrolemember procedure to assign a role to a user:
EXEC sp_addrolemember 'log_users', 'pa_user_01'