I also disagree with the idea of backing up the private key. Generating secure passwords is hard and it is infeasible to ask people to use diceware to generate and store their secure backup. And if you aren't doing backups you might as well generate the key on device. For the purpose of revocation, you can keep a signed revocation certificate around in the event you lose your key.
This makes the guide much simpler, as you don't have to spin up a live airgapped system with secure boot for each employee's key generation. There's no need to have a complicated backup flow either.
---
YubiKeys in general are problematic as they don't have a display that can show the action being taken, e.g. a compromised host could display one thing while the user is signing/encrypting another. This isn't a problem in modern crypto hardware wallets, which have displays that show precisely what is being signed, to mitigate this exact threat model.