One would assume that the daemon's context would be given the largest
amount of privileges the administrator feels the user should ever have,
and then trust the daemon to restrict those privileges as appropriate
for various apps.

I'm thinking that, preferably, the daemon would be started at login and
remain running during the entirety of the desktop session.  When its not
handling any active server sessions it would ideally be pretty
low-weight in resources, so it shouldn't be an issue.  It could also be
started on-demand by applications that need it when it isn't running,
but I'm under the impression that SELinux makes it possible to handle
this be specifying the allowed context shifts as necessary.

