What most end users want -- for the machine to do what they want, as often as possible, while bothering them as little as possible
Windows' UAC journey is a microcosm of the space. The real long-term win is defining ground level permissions around common use cases, so that when composed they can alert as rarely as possible.
But that's an all-of-ecosystem change: the OS (providing usable boundaries), applications (updating to use minimal boundaries), and users (understanding what they'll need to approve/deny).
I wrote about this more on my employer's blog[0].
> The real long-term win is defining ground level permissions around common use cases, so that when composed they can alert as rarely as possible.
And this is an even larger effort to implement, especially as agent capabilities change over time (and they are changing rapidly).