Hi tartempion, hope you're doing well!! I know this thread is old, but I too find myself wanting this functionality: use Touch ID to authenticate an administrator to spawn a privileged process as root.
You mentioned that the Startup Disk pane in System Preferences accomplishes this using private API. Were you able to replicate that, even if it meant using private API? If so, how?
My use-case is a locally-run personal project, so using private API is acceptable for my purposes. Thanks a bunch!!