I would still make it opt-in based or with another security layer.
What if an account is compromised right after the lock-in period expires? Wouldn't that allow the person with access to the account to withdraw all SP at once (assuming all SP is unlocked)?