We ask employees to install a monitoring agent based on OSQuery for compliance reasons. It does very little. It queries (read-only) OS meta details about whether or not they're using antivirus (true/false), have a password manager (true/false), the HD is encrypted (true/false), whether or not location services is active (true/false) and a list of applications. I think this is pretty typical. Some companies might go deeper, but I think we're in the norm.