If I were you, I would consider editing the Sudoers file (/etc/Sudoers), where in the file you could limit who can even run sudo. If they're not a part of the criteria you set, they'll get a message saying they're not on the sudoers list. No bueno.
So, after you edit the file with the criteria you want, package it in Composer, then push it out to whomever you wish.
I'm doing something very similar now with our sudoers file. It had entries limiting the use of sudo to being a member of an AD group, but low and behold, a former Admin mis-spelled the name of one of the groups. Anyway, I'm fixing that in the manner I just mentioned above.
Good luck.