In the company I work at, we have something similar for database executions. In Dev you can run anything you want. However in prod, everyone only has read-only access. If you wish to execute something with higher authority, there is a web page we go to, where we can paste the code, a review board request, a ticket number (if available) a business authorizer, and a technical authorizor (other than yourself). It sounds like a lot, but it's usually pretty quick. Every command is then logged (which I believe is more for SOX reasons). It's annoying, but it's not that terrible of a system.
Of course a sane company wouldn't have a bus factor of one for such a process, but not all companies are sane.
At some point, you'll get somebody with full access to your system. You can reduce it into a very small window (at big cost), but you can't make it go away.
1. deploy the system
2. create new admin account with a long random password and/or 2FA physical token
3. print the password out, seal it in an envelope and put it in a safe not accessible to any IT person; place the 2FA token in a separate safe controlled by different person than the first safe;
4. remove all other admin accounts - with the other present technicians checking that no other account will have access
5. if needed, with proper authorisation you can retrieve the password, and implement the required changes (again, with a second person controlling what exactly is being done).
If the systems require changes rarely, then this cost isn't that high.
Backups could be maintained on a regular schedule, including full router backups. Others in charge of this could be given create and append access to the backup systems, but not delete.
Once you delineate split rights and controls, then you can mitigate the severity of these attacks. Yes, douchebag-router admin can still zero out the routers. But you can be in business in less than a day with those configs logged.
Point in case, as parent commentator said, it's not the kind of problem that you solve with technology.
But thanks for assuming I'm some inhumane business exec, or a VC.
I assume one could refine the process by binding sets of commands or capabilites to specific cards.
Would also be rather handy in preventing remote access attacks.