you got it, use the config doc to disable forwarding via mail rules and use the server doc security section to limit who can create personal agents. You cannot restrict who can create/run personal agents that only fwd mail, you have to restrict all personal agents which is always a good idea anyway. If someone needs a personal agent to do something specific that a mail rule cannot handle then it should go through you, the admin, and sign it with an admin ID so it runs properly.