I'm starting to think something like flatpak or snap is necessary, but in a more sandboxed way, to enforce on the user level that certain apps won't have access to certain files. I would like to see options to fully sandbox an app (has it's own separate permissions for certain documents) or not sandbox it at all (for things we trust implicitly that need that access).