The service can run certain components with reduced privileges, but for that it needs the setuid capability.