Bossware, or working machine monitoring software, endpoint monitoring, or whatever turned out to be a key part of making it possible for our data scientists to function. At all. It was the only way we could both protect the incredibly sensitive information about lots of people while allowing analysis work to proceed.
Aside: anyone who wants to talk about doing data analysis without access to the underlying data is cordially invited to explain how to do this to statisticians who only understand R and local Jupyter notebooks.
"But wait!" you protest, "Can't the business work just as well without that sensitive information?". That's a good question! The short answer is no. No, it cannot, and unfortunately there's a great deal of actuarial history behind this.
"But wait!" cry you, "Could you have not simply trusted them?". That's also an excellent question! To which the uncomfortable response runs roughly: how comfortable do you feel with "we trust them" as the primary security controls when some company has your data? Especially when that trust means you might not even know about a breach? How do you think a regulator concerned with privacy would look at "we trust them" as a security and privacy approach?
Unfortunately, I think some forms of bossware serve a purpose. Sometimes it's one of the few options available that enables trust beyond the directly interpersonal.