I think the idea here is cross-platform / runtime pluggability: an app can specify what policies it needs and this thing will map those policies onto the specific runtimes available (containers or VMs). It's basically a container security policy orchestration layer, I suppose.