I think i get your point.
Actually some executable application with legal signature, but others not, even without signature.
Now CCAV how to deal with them?
If the application without legal signature or without signature which would be unknown file to your system.
If the application with legal signature which can be executed normally, no warning, no block, you do not need add them to white list manually.
When you run unknown executable application which will be sand-boxed, which protect your system from damage, and alert pop-up, you can select "Don't sandbox it again", it will be added to trusted application list automatically.
Also you can execute application by right menu "Run as trusted application".
It works as same as your said.
Is it possible to make "Run only safe programs" option work as anti-executable?
i.e -
1. Unknown program execution blocked & when allowed i.e selected "Dont block again", program allowed with no further block.
2. Whitelisted program allowed with no block.
I think would be good if "Run only safe programs" option work the above mentioned way.