Currently, it is not possible to grant a system account the permission to only renew/create a new system account token for their specific account only.
If a customer has a very restricted role for an account such as "Certificate Admin" for certain control planes only, and they want this system account to only be able to renew their own access token, and no other tokens, they are not able to assign a role that only allows the renewal of the specific system account's access token