Since the Query Tool uses Content Server queries, extensive use can have impact on the overall system performance, potentially impacting other users.
Thus, only certain users should have access to this power user tool.
Please provide a simple (server-side) configuration of user groups that are supposed to have access to the advanced query tool.
The Studio Client part of the plugin should only activate when the user is in at least one of the configured groups.
The endpoint added by the Studio Server part of the plugin should check that the requesting user is member of a configured group, too, to prevent DOS attacks.