Treating the symptoms, not the disease
Unfortunately, this¹ is exactly what most companies do when faced with this sort of issue. They say "oooh, the <command> is far too powerful - let's remove it, or require an operator to get approval from the change board before it's used in future"
Although Joyent have said they are instigating a full investigation, they will find that their system has so many fundamental holes designed in that fixing them all will require not only a total re-write, but a complete redesign of their software and operational practices. A prospect that is likely (considering how poor the whole discipline of system design is) to introduce as many new problems as it fixes.
So ultimately I fully expect the expedient solutions to be applied: an extra layer of checks that will slow down operations and make life for operators even more exasperating (such as an "are you sure" dialog after every command) and will soon become ineffective due to the pressures of getting stuff done (a 10% decrease in operational effectiveness is never paid for with a 10% increase in staff numbers) and management cuts.
[1] yes, satire: I get it