Your comments

Two factor authentication for a group of users with sensitive data, so that remote access needs to be explicitly granted by them (they have the authentication codes).  This is the only solution where they can grant access without being present at the machine, but tech cannot access at will