Otherwise, if “user” has the SELinux user “staff_u”, the user will typically need to write “sudo -r unconfined_r -t unconfined_t”, which is annoying. If SELinux is disabled, these fields are ignored.
For consistency with `su` and policykit, grant access to group qubes rather than user user.
misc