1. Proposed title of this feature request Need barbican policy to be configured to include a read-only role. 2. What is the nature and description of the request? Customer(s) has the requirement of read-only admin role for all OpenStack core services. 3. Why does the customer need this? (List the business requirements here) A read-only admin user is necessary for customer environment. Additional info: The following bug is raised for keystone to add role. This role can be configured in policy file. Bug 1228474 - [RFE] Read only role for tenant access (edit) https://blueprints.launchpad.net/keystone/+spec/admin-readonly-role