They're both gatekeepers. One is for iOS apps, the other is for websites. I'm not sure how "voluntarily" is a relevant factor here. People can and do install alternate roots, especially back in the days when letsencrypt didn't exist and the WebTrust/CAB monopoly was charging tens to hundreds of dollars for certificates.