I could see how allowing the user to whitelist individual scripts would make sense, but as far as I can tell that's not how it works? A blanket policy of "all scripts are forbidden unless wrapped with fragile and shady-looking hacks" doesn't seem particularly useful.
Unless you get a 2nd person on the team (working remotely), and they want to be able to sign scripts as well?
Unless you get some sort of automated CI/CD system?
But I guess here we have some of the underlying problem.
If something just executes whatever you throw at it, people complain.
If something doesn't just execute whatever your throw it, people complain as well. ;)
Why block execution of PowerShell scripts when batch files, WSH scripts and plain executables can still run? You could try to prevent those other kinds of scripts from even getting onto the machine, I guess, but then why wouldn't you simply do the same for PowerShell scripts?
The AllSigned policy where it asks you explicitly about trusting new publishers[0] seems like what I'm asking for, except that it apparently requires the certificate to be installed in Trusted Root Certificate Authorities! That's way more trust than should be necessary.
The only option that seems to make sense (aside from Unrestricted) is buying a certificate from an existing CA that's already trusted, so that users don't need to trust you with acting as a CA, but that's quite expensive.
[0] https://www.hanselman.com/blog/signing-powershell-scripts
Sadly some software I use is so old that the only way to call Powershell scripts is via a batch script...