This may be of interest:

http://www.securityfocus.com/columnists/367

In this new model, new application files are detected in real time as soon they appear on systems and are automatically added to the automatic graylist. They can be easily approved or banned, based on current security policy.