Remember that the "real" protection against unauthorized users accessing areas or functions of your application is in the Controllers! However, best practice is to avoid "tempting" them to click on something that they are not authorized to do anyway.
We will explore a few approaches that we can use.