I think PolKit can be used to delegate fine-grained control to users. Which other tools are available on Linux to control users' access to fs and network resources? File permissions, systemd-nspawn?
selinux is the primary one that comes to mind, it definitely ticks the "fine-grained control" checkbox for sure