But, usually a company of this size/scale puts in place restrictions so that accessing privileged abilities like this is extremely difficult and requires authorizations / clearances / permissions from users, etc.
Generally big / public tech company employees are not even allowed to LOOK at PII or the data of a specific user name etc. You run all tests on staging / fake populated DBs only, etc.
CEOs don't get to break the rules just because. These kinds of restrictions exist to protect consumers (and their data) and the business legally from liability, etc.
It's not that people didn't know the admins have the power; it's that people didn't believe they'd use the power.
Your local police or military could just barge into your house and kill you at any time. They have the power to do that. Society functions to the extent that you don't believe they will do that. If you found out one day that your local police chief had, under cover of law, busted into someone's house and waved a gun at them over a petty personal dispute, though, your faith would be a little shaken.
People have the power to do a lot of things. You have the power to quite easily lie, cheat, and steal in this world. When you run a website, like when you run a business, you have to convince your customers/users to trust you not to do those things.