Answer yes if administrators, meaning anyone who can access other users' data, change security settings, or manage the underlying service, are held to a higher standard than ordinary users, for example time-limited elevation, approval workflows, or separate privileged accounts. Having an admin role is not sufficient on its own - this is about the extra controls around that access. Describe the mechanisms in place in the notes section.