Since it is rogue processes - from the interweb? - rather than rough
users that are the potential problem, wouldn't the cure then be to grant
certain trusted applications RT-privileges?
A novice user would install well-known binaries from the distros
repository. The binary runs as user 'rt-audio' which is the only/one of
the few users on the system granted rt privileges.
jackd would be a single instance for all.
/j