Security Restrictions based on Customer

It would be great if we could restrict Customers from internal IT staff.
Without going into any particular detail there are situations where we cannot have members of certain groups of staff accessing specific clients. We are resorted to locking the users out of Immy entirely, rather than restricting the clients they can access. It would be nice if we could have both worlds.