This is an excellent step for protecting MacBook Pro users against hardware invasions (such as US and China border authorities). If you trust the user to replace hardware, you permit the user’s hardware to be altered by malicious actors. By restricting final approval of hardware replacement to a vetted subset of all humanity, you ensure that it’s vastly more difficult for the vast majority of malicious humanity. Yes,…
The correct way to handle this, however, is to offer to sign the customer's key for a given unit or order, with a mechanism for succession (i.e. simultaneously sign a successor key, and expire the current one).