Disable or restrict "Execute Shell"

There can be usecases where user have permissions to start/stop containers, but can’t modify the containers (e.g Execute Shell).

Is it possible already (or in the future) to restrict who can use “Execute Shell” functionality or way to disable it completly thorugh web interface?