Can I use this as a generic app permissions boundary or do I have to somehow fake it as an "agent"? We are well past the point where I need to be able to lock down that my music player has no ability to read my SSH keys or whatever.
Naturally, this will be gated to corporate customers - the plebs do not get access to better security unless they pay for a top tier license.