This is actually something I’ve been thinking about, mostly on the backburned for managed devices and such, specially for non-technical workers.
I think your problem space shares some of the same issues, e.g. having the tools someone needs available on day one if they’re starting a job. For some compliance issues, I imagine there is also a lot of overlap with creating environments that are running required security checks. For example, for a written exam, having restrictions on e.g., networking.
Given how e.g. Denmark and France seems to be working towards replacing Windows with NixOS, I do hope I can manage to find a way to support a more “typical IT admin” workflow for a fleet of non-dev workplace/teaching computers. I think it would be very powerful to create a real alternative to active directory and the all the centralized management tools that windows currently have.
I wonder if you’ve been considering this for e.g. a monitored exam? Or perhaps, that’s more something the IT Admins would run?