Apologies for the delay, this message passed me by!
Role policies are a special case--they're best thought of ACLs layered on top of the existing, authoritative rules defined in the resource policies. Anything allowed by a role policy
must also be allowed by the resource policies in the same evaluation. Any
(resource, action)
pairs
not defined by the role policy are implicitly denied by that role policy.