User space limits potential security impacts, and a restricted VFS could be used to prevent clients from accessing anything that they shouldn't.
(Although I'm not even pretending to know whether or not this is a remotely good idea - my guess is that it isn't, but I'd like to know just how bad an idea it actually is.)