If you trust someone to manage IT policy in the first place I'd think they'd be smart enough to be able to learn the basics of Nix? Like 95%+ of it is just declaring obvious settings that are already in nixpkgs. In practice it's mostly an ini file, but with the power to do more if you need it.