PM is not my area of expertise, but I do know that you can grant a very limited access to CCS via its roles (aka Segregation) system. You can then allow certain users to run the console (they can just run it off your CCS App Server's \BVSMC share, and it will self-install) and they will only see UI for the features you've chosen.
The roles are configured in System | Roles, and there is a 'Policy Reviewer' role that may suit your needs perfectly.
KDH