You set it in the permissions. You say who can access it.

i.e. If it is applied to an OU, but no one in that OU has rights to run it, it shouldn't run.

Using the Group Policy Management console then under Security Filtering.