Today every admin account has the same power. Any admin can delete clients, visits, invoices and historical data, including the owner's own records. There is no account that sits above the others.
This matters because we grant full admin to new managers on purpose. Limited accounts cannot see history from before their start date, which makes them unable to do the job. So we trade data security for basic functionality.
The ask:
  1. One owner-level account per business that cannot be deleted, demoted or locked out by any other admin.
  2. A published data backup and restore policy, so we know what is recoverable and how far back.
Related and worth merging with: Automatic backups of schedule and client information (currently 16 votes). Granular Manager Permissions covers limiting managers, which is the other half of this. It does not protect the owner.