By default, local not domain admins have privileges on the server. Of
course, many orgs have domain admins in the local admin groups. Local
admins with no other role assigned in SPS can basically read and set
security on any folder or file in the system, but not create or write
ect. This allows an org to never "lock" themselves out of any doc. No
way to remove this special access, the best way to deal with this is to
limit your local admin groups.