Creating positive TTPs, or full accepted behaviors would leave less place for the unexpected.
Imagine a space mission where every potential action is planned and the reaction is thought over, tested and practiced to perfection.
We whitelist network traffic, applications installs - so why not full functionalities? We are probably far from a world ready to accept this. But between limiting the users behaviour to a level which causes annoyance and creating a more secure experience it would be interresting to find the balance point.