Tango Access Control security

Hello tangoers,
we made some tests with TAC, and I would like to understand a specific point: is there any way to block the possibility to bypass TAC by an environment variable?

In the case of a computer which can be accessed by anyone, one would like to avoid anyone who can access to a terminal to have write access to any device.
Is there any way to avoid this?

Thank you.