Which Functions runtime and storage-extension/extension-bundle versions did you use for the role-removal test?
There is a distinction to capture here: Microsoft's current permissions table lists Storage Blob Data Owner + Storage Queue Data Contributor for the blob trigger, and additional Storage Queue Data Contributor + Storage Account Contributor permissions in host-required storage. This is separate from the base AzureWebJobsStorage requirement: learn.microsoft.com/en-us/azure/azure-functions/m…
Since your host and trigger share an account, including the exact versions and a fresh host start after removing the role would help readers reproduce your result. The specific denied operation in storage logs would also help explain any difference from the documented permissions.