I am certain this can be done, though I have never personally had a need to do it.
I think you have to make your application the shell for that user and then restrict access of all other applications.
This article shows one way to do it that you should be able to customize for your application:
http://www.novell.com/coolsolutions/trench/3458.html
Martin Fredrickson
Test Engineer
Northrop Grumman
Advanced Systems and Products
San Diego, CA 92128