The correct configuration is Service Territory Member. The Service Territory Member record links a Service Resource to the territory in which the resource works. That relationship is fundamental to territory-based scheduling and sharing calculations for appointments assigned to the resource.
Field Service access combines Salesforce object permissions with Field Service permission-set licenses and managed sharing. The correct design applies least privilege: technicians, agents, dispatchers, contractors, and administrators should receive only the capabilities required for their operational persona.
The alternatives address different parts of the Field Service model. User Territory links users such as dispatchers to territory access groups; it serves a different persona and sharing purpose than the resource-territory membership relationship.
This approach follows least-privilege design and keeps access changes maintainable as resources, territories, assignments, or user responsibilities change.
This approach keeps the implementation aligned with the standard Field Service data model and avoids unnecessary customization. Study Guide reference: Permissions and Sharing — Service Territory Members; resource-territory sharing.