> Even when provided a means to instantiate virtual machines where they can have root access within the virtual machine, a lot of them will bitch.
Well, yeah. I spent a year or so doing all my work in a VM (for other reasons) and it sucked.
> proudly ignorant to how fast the sensitive medical data or financial data they're working on can fly out of the machine
Hey, this is an easy choice! If I can have local root XOR sensitive production data on my machine, I pick local root. Keep that PII the fuck away from my disk, please!! (Hell, do that whether I have root or not.)