No, by definition the superuser has all permission to perform actions on the system. You can change who the superuser is, if you choose.
Without strong authentication via Kerberos, you're wasting your time trying to apply any kind of authorization rules to your system because anyone will be able to masquerade as whoever they want.