This actually works… They successfully back up their files to their account with 0:0 ownership.
But, of course, they are not root on our end so they either lose the ability to write or change the files… Or they lose the ability to read them at all.
The easy solution is this neat rsync argument —fake-super … but I guess you could make this mistake on purpose with permissions that allowed read access to all … and successfully create write once, read, only backups…