You might want to check out firejail - https://firejail.wordpress.com/ - it supports seccomp as well.
What it means in practice is (for example) a daemon running under firejail must be able to open log for writing and open sockets. An application which uses seccomp natively can first do those things and then block all further open/socket syscalls.