Hi,
From a purist perspective it is not truly 'securing' an application but I work on the philosophy that if a user can't see an attribute or business object and has no way of accessing that attribute, business object, form, query, report or whatever then whether it is truly 'secured' from them using access levels is pretty irrelevant.
On that basis, there are a number of ways to 'secure' AwareIM on the fly from users based on checkboxes in their profile or whatever. I will often do such things as putting certain elements on a form section (tabbed or sequential) and then show/hide that section conditionally based on conditions related to that object or in your case conditions related to the LoggedInRegularUser. Similarly, I will control the visibility of certain operations whether placed in a form, query or presentation based on similar conditions.
I have found through experience that it is often far more manageable to limit the number of Visual Perspectives and Access Levels to the minimum number possible and whereever it is feasible, to limit 'access' or more accurately 'visibility' of access using rules which are entirely flexible.
We are working on one project right now where there is no menu at all. All of the information presented to the user and every choice that is offered to them throughout the application as to what they can do is controlled dynamically. The home screen is a presentation that only shows them what I want them to see and access what I want them to access.
Often one of the biggest challenges that new users face is accepting the different paradigm of AwareIM and realizing that there are often dozens of ways of 'skinning the cat'. If you search through this forum for responses from Support where their response was "Just not possible", you won't likely find very many.
Good luck with it,
Pete