Investigate Magnum policy more to tighten up config
Magnum has moved to policy-in-code in line with other projects
The policy.json should exist as a set of over-rides of default policy-in-code, so this MR will tighten those over-rides, starting from full defaults.
Edited by Paul Browne