Let's take filesystem access on linux for example. You can run as a user without permission, or you can configure something like apparmor/SELinux to stop the program if it attempts do do something not on the list, or you can use containerization to build a limited world for the program to see...
But isn't this all a bit adhoc? The fundamental presumption is of unrestricted capability and then the OS provides options for restriction.
Perhaps I've misunderstood it but I think capabilities are inside out from all of that: You need to walk, so here are some legs. You need to swim so here are some fins. As-is it's more like: you can't go over there so here's an ankle monitor.