Some processes run as root (the prelogin and the daemon for instance)
convert these to an less privileged account still protected from local user accounts. Note that it needs to be constant and access needs to be provided to the data/prefs directory and the Unix Domain Socket.
Note: "You can use Open Directory services to obtain a locally unique UID"