Maybe better as locking trigger. When a system detect the previously authenticated user is no longer the active user it could lock keychains, tokens and sudo timers. This is less intrusive compared to locking a complete system every time you take a step out of the room.
It doesn't seem like using it for automatic 2FA would be practical. For one thing, it wouldn't allow for password managers, and if the environment changes significantly it wouldn't match up (on mobile, using an on-screen or touch keyboard, finger pecking on a laptop while eating at the dinner table, etc.)