For things that, historically, didn’t require any additional authentication, both macOS and iOS are moving in that direction, I think.
On MacOS, applications by default don’t have the right to read your disk and show a list of files, they have the right to ask the OS to show a dialog that reads your disk shows a list of files, lets you pick one, and then grants that application the right to read that one file. Similarly, for saving files, the save dialog runs under OS control, and grants an application to write a single ‘file’ (which, on macOS, could be a directory containing multiple files)
Similarly, on iOS, apps can’t read photos, but can ask the OS to show a photo picker.
MacOS (¿still?) has system preferences that allow users to disable such checks, though, granting full file access to certain apps, for example, and also will ask users to grant apps the right to read entire file systems when they try to do so.