Can any recent (including current) Google employee tell me? On MacOS there is a binary authorization system GitHub - google/santa: A binary authorization system for macOS. Not sure if it allows nix, and not sure if they have something similar on glinux.
If you want to answer but don’t want to thusly talk about your employment in a public forum like this one, please DM me.
When I worked there, I had non daemon nix running on glinux. Mostly used it for the moments where you need some tool, but don’t want to go hunting through debian repos for it.