Hey @Recollectr!
@alexmurray please correct me if I misunderstood your suggestion, but the explanation can be found here. In that case system-files
is prefered since the snap is built with an interface hook, and hooks run once system wide.
Sure, your snap will still be kept under strict confinement. Publisher vetting is required due to the sensitiveness of this grant. Since this could allow sandbox escape (even under strict confinement), the user/ecosystem would have to trust the snap (and the publisher behind it) to behave rather than the sandbox. The linked post explains this as well.