Macola uses SQL authentication to access the tables while the user is in the software. You can lock down the NT user names either directly or through groups and use the db_denydatareader and db_denydatawriter functions to the various databases and Macola will still function. This should include ICR's as well since Macola passess the Macola user name and password for running those reports. You would be limiting or denying access to Macola through outside Crystal reports, MS Access, Query Analyzer or other tools that can read a SQL database.
Kevin Scheeler