The first user in a workspace becomes the Owner and holds every permission. Everyone else gets only what you grant them.
Permissions are grouped by area — sales, purchase, inventory, accounting, users and company settings. A role is simply a named bundle of those permissions, so a Salesperson might have sales access but no accounting access, and an Accountant the reverse. Assign roles to people rather than granting permissions one by one; when someone changes job you change one role instead of auditing a list.
Every meaningful action is written to an audit log with the user, the time and what changed. Combined with roles this answers the two questions owners actually ask: who can do this, and who did do it.
For extra protection each user can enable two-factor authentication from their profile, which requires a six-digit code from an authenticator app at login.