Hi,
that is not correct. All users can access to PPAC, no matters the security role that the user has. Simply the actions that the user could be to do in this portal are restricted with the role assigned.
In your case, related with the role neccesary to import solutions. You could use alternatives like the account to import solutions is managed by an admin or deployer team. Or use ALM integrated with GitHub actions or Power Platform Pipelines, where these accounts are impersoned.
At the moment that a persona have to import a solution manually, there is the "risk" that this persona has a system admin rol and could manage the environment.
In this situation, a good training to this people is very import by trust and delegate this task.
-------------------------------------------------------------------------
If I have answered your question, please mark your post as Solved.
If you like my response, please give it a Thumbs Up.
Regards
Alberto