FWIW, If you don't require the single-pane management, some scenarios can be simplified by deploying additional individual clusters/instances with separate access rather than controlling only via policy.
Mentioning since I've def seen people get stuck and forget to consider the obvious.