dockerd can be extended to support an access authorization plugin. https://docs.docker.com/engine/extend/plugins_authorization/
Ratify plugin can be extended to support Authz so that all content fetch commands (image pull, build) can implicitly invoke Ratify and allow/deny the pull operation.