This change will help oslo.policy consume different levels of scope
and enforce proper admin-ness across OpenStack. The idea is that once
keystone has the ability to issue system-scoped tokens, we can start
enforcing partial scope checks in `Enforcer.enforce()`.
bp add-scope-to-policy
Change-Id: I7fa171d859d82939511f8279e4e9464f792ed2cd