This adds new defaults roles in os-instance-usage-audit-log
API policies. This policy is default to SYSTEM_READER role.
Policy rules are made more granular to adopt the new defaults.
Also add tests to simulates the future where we drop the deprecation
fall back in the policy by overriding the rules with a version where
there are no deprecated rule options. Operators can do the same by
adding overrides in their policy files that match the default but
stop the rule deprecation fallback from happening.
Partial implement blueprint policy-defaults-refresh