Apply systemd sandboxing by default to some services

Would dropping SystemCallArchitectures=native simplify syscall filter?