@lanodan It you expose all these services via unix sockets, then you can control access to them in one place: via file system access (eg: restricting access to file system).
I’m not sure if this is in line to what you’re referring to with “controlling them in one place”.