Currently, when you start your favorite GUI based editor, and tell it to open a file, it calls on the OS to present a dialog box, who chooses file(s), those names are then passed back to the editor. The editor then uses the users permission to open the file(s), and allow you to edit your data. Note that there is NOTHING stopping the program from getting confused or malicious and opening any arbitrary file using that user's account.
The exact same workflow happens in a Capabilities based OS, except the names of the parts and constraints (that you don't see) are different. It works exactly the same, as far as the user is concerned.
Instead of calling on the OS to present a dialog, then directly accessing the files, the program calls the OS to present a PowerBox to the user, and it returns capabilities to files or folders, the program has NO access to any other folders or files. No matter how confused or rogue the editor can not corrupt anything outside of the objects specifically chosen by the user.