System users are currently added to administrators group and have to be restricted further to specific parts of the JCR tree (paths other than /lib, /var, /tmp).
This could be done by creating a system users group with restricted paths, and then modify the system users creation to be part of this group instead of administrators group.