I instinctually agree with nkrisc, but this is an interesting line of thought.
What's an example of something that nobody should be allowed to do e.g. on a laptop? If I buy a system with OS stuff set up from the get-go. What abilities do you withdraw from the user?
>What's an example of something that nobody should be allowed to do e.g. on a laptop?
Clearing required efi variables, bricking the motherboard.
https://www.phoronix.com/news/UEFI-rm-root-directory