The reflect UDF is unsafe given its ability to execute arbitrary user code in Hive's runtime and in a Sentry environment it will be blacklisted by default to prevent its use.
Enabling it would defeat the purpose of data protection. Would you or your users be able to instead add in a custom, verified UDF that directly does whatever reflect was being indirectly used for? That'd be the safer route to go.
You can choose to whitelist the reflect UDF but I'd strongly recommend against that.