Best way to reliably restrict/redirect feature (not security) access based on a different db field's (scenario in post)

I use the Globals steps (NodeJS only I think; steps that run on every page load, server-side), check the current route and use the Redirect step if applicable

See the user’s screenshot and my reply: (ignore the Security Restrict, assume it’s a Redirect step)