Right - going down for a day can be damaging enough for some companies. Not allowing one person to click the "erase" button in the first place should be the focus. How hard could it be to implement a system where two or more people have to issue a command before it runs?
Point in case, as parent commentator said, it's not the kind of problem that you solve with technology.