Use Linux file capabilities to control privilege rather than set*id (this is orthogonal to USE=caps which uses capabilities at runtime e.g. libcap)

Packages describing “filecaps” as local USE flag

Package“filecaps” Flag Description
app-metrics/collectdWhen set collectd daemon will have set required capabilities to run most plugins even if run as unprivileged user
net-libs/libopingAllow non-root users to use [n]oping utility.
sys-process/criuInstall the criu binary with file capabilities to allow for rootless CRIU
x11-misc/i3statusLinux capabilities library is required for i3status to be able to read net bandwidth