Add config for the new device management role

And fixed first-id values for some <staging-public-group> for T as they
had incorrect values set.
Also exposed the requied permission for the role as SystemAPIs and added
role protection level.

Bug: 200680394
Test: N/A
Change-Id: Ie3693c6d4d57e2faa4c61f675a119a23326f5247
6 files changed