*** I am not a programmer, so forgive if this is a dumb question ***
It looks to me that the program has to be specially written an compiled to use it. If this is so, it reminds me of SELinux Strict-Policy vs. Targeted-Policy". Programs that are written to cooperate with the filters are already vetted. Maybe a better (or worse) analogy would be the people who agree to a background check for a TSA "frequent flyer" pass, except that it's the people who had the background check and get the pass that are submitted to the screenings at the checkpoint while un-vetted people skate through the no-inspection express line.