You can choose to set up non-global zones that do not participate in the cluster. A root user logged into one of these zones will not able to discover or disrupt operation of the cluster.
To implement this feature, create the file /etc/cluster/cluster.zone.deny in the global zone of each node and add the names of the non-global zones on that node that should not be part of the cluster. If the zone name appears in the file, all cluster commands and daemons are disabled in that zone. Ensure that the zone is not running when you add or remove a zone name from this file.