Shared signatures can be limited to either a specific container or a specific blob. They can then indicate what permissions they give (read, write, list blob), and they can indicate how much time they are valid.
The only way to create an SAS is to have a storage key, but anyone with an SAS can use it to do what it allows them to.
Sounds like you want to let all your customers write drops, but not read them? If so, the SAS, which sets only write permissions, should do the trick.
, ( ) ? , , , - (-?), SAS , . .