This is really the ideal approach for key security, but does add a bit of friction.
I think many people will be happy with login from root key over QR code as implemented now, but the more cautious approach will be NIP-26 style delegated keys.
Especially useful for enterprises and shared or company accounts as well.