Consider cash in your wallet... you quite easily hand out tokens to clerks for transactions.
Instead of a dialog box run by an application to open a document, you have the OS do the same thing, and enforce the decision of the user. As far as the user interface, the same steps would happen, but security would be radically improved.
Broad based permissions are horrible kludges, and make explaining fine grained capabilities much harder to do, but I don't have a better term for it.
If some random application wants to phone home, you could allow it, or not, or give it X amount of bandwidth, the options are limitless. I don't know what the optimal conventions we'll settle on will be. I know if I were to specify them, they'd definitely be the wrong ones. ;-)