Hi phyndman ,
thank you for your suggestion.
In fact, you can enforce that the end user HAS to accept a remote support session on their device by deactivating the toggle "Access attended managed devices without end user consent" (first screen shot) for any agent who should not be able to override end user consent. You can find this setting in the Admin Center, when you navigate to the specific agent and then hit the "Settings" tab at the top (Users > Settings). Note that agents may need to log out and in again for this change to become effective.
Once the setting is stored, agents will see the screen as depicted in the second screen shot, missing the button to "Connect now". That should accomplish what you are asking for. Does this solve your problem?
Happy to assist you further, if needed.
Best,
Daniel