Not all roles require the same level of audit. In general for simplicity, an entire firm will use one system that just applies the same policies for everyone, but a dev building a web interface for an internal risk tool will not be under the same requirements as a sales trader talking to clients and taking orders to execute in the market on their behalf.
I believe you can still provide chat transcripts from Slack without managing keys yourself.
and you can still intercept all the SSL if you just roll out your own certs to all the workstations and the firewall opens everything..