Hi Peter,
I guess the only option is to restrict IMA11 business transaction like Approval / Release from all roles.
When the work flow is updating IMA11 transaction, it should not pick the user ID, rather than batch user ID, by which it will have SAP All access. This requires ABAP and Workflow help.
Regards
Terence