So, I am guessing these normal people will have devices enrolled as 'work managed' AfW devices. That mode disables the personal play store and only allows the work managed play store. In order to allow a 'super user' access to the personal play store, you would need to exclude them from 'work managed' mode and have those devices enroll into AfW using the 'work - profile' mode (basically byod). This mode electronically separates the corporate data from personal data. It creates two of everything and puts a locked briefcase icon on all corporate data.