This idea is based on the discussion in this question in the forum.
The boiled down idea is basically to have a substitute Technical App Contact so that not just one person is able to change the node permissions at a time
Same problem here.
What could also work is to expand the company admin role with the same (technical app contact) permissions.
For on premises customers, this is essential.