Instead, permissions should be implemented at the OS layer, not just for Mac app store apps. Here's how it would work:
- An app could specify a list of permissions, like on Android.
- One of the permissions would be "unrestricted", which is equivalent to today's unsandboxed apps.
- The first time you try to run an app that requires unrestricted permission, macOS will tell you the app could be dangerous and ask for confirmation. This is similar to how Gatekeeper warns about unsigned apps, but here the focus is on what the app can do, not who made it.
- If a legacy app didn't specify a list of permissions, it would be treated as "unrestricted".
That way, there's no incentive for developers to leave the Mac app store. Security is increased for all users, no matter where they download the apps from. This mechanism doesn't restrict the power of the platform, what developers can do.