Regex option in PAM to blcok any commands in /apps folder

I have the below requirement in LInux server integration to PAM. Kindly help.


I have privileged accounts [pam_appadmin and pam_appvendor]. The requirement is:


pam_appadmin should have full access to /apps directory.

But pam_appvendor should not have access to /apps directory - using any command, PAM should block.


Is this doable via command filtering / reg ex?


I know this can be done in Local linux OS level - access rights. But I wanted to check what is the use of regex, and can we use the regex for this requirement.