Second, even when your metric is security, creating a policy that people have to circumvent to get their job done seems likely to reduce security.
> when it comes to ensuring what data comes in and leaves your environment there's little choice
The concept of your environment having an "inside" and an "outside" is dangerous. Better to assume that "inside" is just as hostile as "outside", and avoid having any insecure internal services or resources. Use TLS/HTTPS everywhere internally, require authentication for internal services, and otherwise make sure that an attacker gains nothing by compromising an end-user system except what's on that end-user system.
> If your job involves idling on Freenode
Forget "idling"; participating effectively in many Open Source projects (whether developing them or getting support for them) requires the ability to get on IRC.
> maybe take it up with management
Short of C-level executives, management rarely has the ability to change IT policy.