Using "not"/negation rules in Identity Role Based Access Control (RBAC) policies?

Hi folks,

I was wondering if it is possible to use negation rules within Keystone's policy.json:

I would like to make a rule that says "only allow deletion of users if user does NOT belong to the services project"

Is this possible? Have others run into similar use cases?

This document explains the policy.json file for Mitaka and indicates the use of 'not' to limit access to APIs.

