vcloud vdc with two different admins

i have a customer who is the legitimate admin for its own vdc, but i should manage a vm AND the customer should not reboot or do anything bad with that vm (but be admin for the rest of the others).

i have asked the customer to create a normal user for me and assign ownership for the vm to me, so far so good, but what could defend me against a bad customer admin that reboot or delete that vm?

only relaying on logs is not very secure for me, once that vm is gone it will be only support problems between me and the customer, you know...

