It would be nice to grant permissions in a fine grained way and not just have a blanket accept or reject. For example, if I download a weather app, chances are it will want location and internet access. If I don't want it to have my precise location I should be able to deny location but grant access to the internet.
If you want to build the allowlist yourself, doesn't firejail already do what you want?