Is it possible to assign a role that enable the user to execute policies, but not allow them to add/delete/edit policies?
It would also be helpful to assign permissions based on Group membership or some other construct where devices belong to an organisational unit. - For example, delegating controls to a regional IT team, or to a team that supports end-user devices, but should not be able to manage servers.