Isn't this the whole point of SELinux, AppArmor and a host of other security policy enforcement systems we already have? It's already enough of a challenge organizing/debugging the interaction between the current layers of enforcement, without adding yet another one.