you should be able to control what they can write to via Read only role properties These system properties control the snc_read_only role