Add role allowlist for restricted permissions

Test: Manual
Bug: 158311343
Change-Id: If14c9c667b98a92e3e29efd572567f5ea3cc61d3
7 files changed