This is a modern approach, seen most prominently in Android right now, to address the reality that the fundamental tenant still driving desktop security models today—that all apps running on behalf of a user should be granted the same privileges and permissions—is no longer a valid way to design a security model.