If you want to run unsigned software or extensions you will have to boot into a recovery console and change the security model. The warning dialogs will be enough to discourage most use. Things like ApplePay and iCloud may be disabled depending how far you reduce security, but you'll be able to do whatever you want.
I think it be a great solution to have a more uniform solution across all devices and platforms. It would create a boom in the hacker community, while still keeping >99.99% of users running from sealed system snapshots.