The reason this feature is there is that many extensions play poorly with or should not have access at all to specific sites. For example, Grammarly has no business accessing a corporate billing system and IT might want to disable access. In other cases an extension slows a site massively and a user might want to say, "not that site" to an extension. This could be the start of a big end-user improvement, especially if it can be managed by users and installers.
And "it's confidential" is the worst possible answer but it's still the one they gave us.
> The best faith interpretation I can come up with, is in fact for security purposes. It creates restrictions on (at least from Mozilla’s perspective) untrusted extensions. I mean how many extensions are there that do act maliciously? It probably isn’t trivial.
My best interpretation of that is it allows organizations to more easily allow some extensions while disallowing others.
This is of course, complete speculation and if it was for enterprise management reasons, Mozilla should have clearly communicated it.