You can add the user to the following role so that the View File and Accept File Delay commands specific to FTM are restricted. Please see the XML below:
<role name="Restrict FTM viewFile">
You can use this with your other existing roles but please ensure that your current 'combineMode' setting for Authentication is set properly as it can either inherit the highest possible permissions or the lowest. Please see the Authentication section of our documentation for more details.