The thinking of "we don't want the system to not work if it's needed" thinking demonstrates a failure to understand the prior probabilities involved. Most of the time the flight conditions will not warrant activation of the MCAS, and apparently the system is sufficiently unreliable/easy to damage that the chances of the system inadvertently triggering is high. But Boeing wanted to be sure that MCAS would always activ…
This is assuming that the system is necessary for certification or safety, if it is not necessary for certification or safety then it shouldn't be there at all.
The fact that Boeing put a secondary autopilot in there with a single point of failure, can only be explained by organisational failures reminiscent of the Challenger disaster.