>What's an example of something that nobody should be allowed to do e.g. on a laptop?
Clearing required efi variables, bricking the motherboard.
https://www.phoronix.com/news/UEFI-rm-root-directory