The only other suggestion I would make is you could set up an employee group of the valid users for the action, in the inbasket display you could display a message that they are not assigned to take the action, and in the flow when the approve action is taken check to see if they are in the employee group and if not reroute back to the User Action.