Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection modules or does the tool have a significant risk surface? 2) What was the threshold set for quarantining? Does it make sense in this case? 3) Is/should your device be part of a "Developer" policy that is more permissive? Are all users of the tool impacted? 4) Does this happen frequently? If so, should definitions be manually pushed in batches so everyone is not nerfed at once. 5) What is the process for the developer to report/fix the false positive? Is the response time sufficient?
I'm probably forgetting a few. The point is, shit happens (especially with technology). You respond, fix, and hopefully learn. If shit happens a lot, its either because the tool owner doesn't give a shit or the product is shit itself. The delicate balance of security and business operations/innovation is all about weighing and evaluating risk/benefit.