I think a time-lock feature to enable “I know what I’m doing mode” for a year, after a 48h delay would be ok.

Or something like that

I like Chrome OS's approach where you essentially choose your security level at initial setup, and need to wipe your machine if you wish to change it.

But what if a scammer walks grandma through backing everything up, unlocking the machine, installing a rootkit, and then restoring from backup? /s

(Joke is on you. You thought you'd be given access to app data to back it up? That's against the security model.)

No, that would still suck.