MB it`s a bit late, but now you can use "Bouncer" or/and "token.abilities" to control which data and actions should be available to active/inactive users.