Personally I'm tired of arrogant people that have to be spoon-fed.
Simple example (to do it in more detail would take a long time):
Start computer, OS owns all rights, drivers and subsystems/daemons started with the rights given to them.
User is in control, he starts a program which uses the default rights given to it. The program wants to check for updates but doesn't have the rights to access the Internet. It is halted and the user is prompted to either allow or disallow Internet access. The user accepts the access and the program continues.
There is no need to separate each part into a user to give them separate rights. That's all I've said and all I meant.