Even with non-global zones it would be great to have different users for different services. You can better watch and control resources like CPU and so on. prstat -a in the global zone is good example.
For security reasons, it would also be a strong recommendation to separate user between the services. It'll be not the the best idea, to run the whole webstack (apache, squid, glassfish, tomcat, mongrel and so on ) with the same userid. This message posted from opensolaris.org
