It's amazing to me that we're all so chill about a company in Redmond having root access to our PCs because they pinky-swear they will never misuse it.
For example look at how many "patch tuesday" update fails there have been... I think it's sometimes a good idea to not always apply new updates immediately for this and other reasons.
And then you’re back to trusting an external third party, just slower and with greater expense.
Waiting for others to hopefully discover targeted security vulnerabilities and only updating after an ad-hoc timeframe if nobody shouts “FIRE!” isn’t a security posture, it’s just terrible patch management.