MQTT Transmission Write Permissions

I want to expose the “Device Control/Rebirth” NCMD metric for my MQTT Transmitters but ensure no other tags can be written to via MQTT so that data consumers can discover metrics, but don’t accidentally get control permissions in my plant. What is the most robust/secure way of achieving this?