Project variations, variation rows, project phases and budget deliverables use the same budget permissions as the project budget screen.
What you need
Create Budgets (or project-role Budgets Edit) — create a variation, including one that creates its linked opportunity in the same step
Read Budgets (or project-role Budgets View) — open budgets and variations
Update Budgets (or project-role Budgets Edit) — change variations and their rows; approve a variation by changing its status; add or edit project phases; add budget deliverables
Delete Budgets (or project-role Budgets Delete) — delete variations and remove phases
Without the matching permission, Drum redirects with You are not authorized to perform this action.
Nuances
Approving a variation still only needs update permission — there is no separate variation-approval right, and Approval Settings does not route variation approval.
Creating an opportunity-linked variation does not also need Create Opportunities.
