Thanks Colleen,
So for this particular case, inactivating both the objects S_BTCH_NAM and S_BTCH_ADM will serve the purpose of allowing users to only create/change or delete their own jobs but we still have the risk that it allows the users to execute the programs that are not classified under any auth group.