Why not just deny those users read access to VA?
You don't need RLS for that, just set the permissions on the top folder of the metadata tree or in the default ACT.
I think you can create web pages that hides the url and even functions that removes them in the browser, but that seemes to be a lot of work when you instead can limit access via SAS Management console and metadata.
Just my 2 cents 🙂
//Fredrik