One compromise to consider is using the unconfined domain (unconfined_t) to offer a more flexible arrangement. Of course this won't help you in a compliance situation (like PCI/RMF/NIST) but it's worth considering.
https://wiki.gentoo.org/wiki/SELinux/Tutorials/What_is_this_...