thanks - I was thinking about non-OS executables
so for example, could I assert that only the following were allowed to run
1. core OS executables and libraries
2. manually selected 3rd party software eg from the play store or side-loaded apks
( 3. and nothing else )