This destructive admin operation needs confirmation from a second, distinct admin.
Break-glass policy: a single principal cannot authorize this alone.
Have a second admin approve; the response carries a confirmation_id and an expires_at_ns window to use.
Every RelataDB error carries a correlation_id (UUIDv7). Cite it when reporting — ops cannot trace the request without it. See reporting errors.