I think this subsystem should model some of the pubkey restrictions implemented by OpenSSH and others. E.g., "this key can use the sftp subsystem but cannot forward any ports." Some such restrictions may be platform specific and therefore do not belong in your I-D. But certainly some are generic. Cheers, Nico --