I have literally never worked at an organization that had any clue what its configurations should be, and they wouldn't know how to validate them if required by law. Most installations are not sufficiently large, and most sysadmins are not sufficiently competent to use tools like this anyway.

This dismisses an important kind of validation, sanity checks, which
can occur *without* declaring policies in advance. E.g., are your
settings reasonable? Do your mx records point to mail servers? Do your
filesystem mounts point at fileservers? Etc. This kind of tool could be
used by anyone, but we are too busy solving our own problems to provide
something "practical" for people with less expertise than us, that might
not be "practical" for us because we need more functionality than that.

