You can change the permissions to restrict access to the tape device - make sure that you change both the long and short versions of the names of all the device nodes associated with that physical device.
Even rewinding and ejecting is not foolproof; the fool can always walk over and re-insert the medium.
If regular users have a legitmate need to write to the tape device then things get more complicated. Probably the most fool-proof method is to install another tape device with open permissions and the original is only writable by root - of course, if the fool is 'root' then you are still in trouble.
If it ain't broke, I can fix that.