In Riot (the most prominent Matrix client), you need to log out to change your password. In the current version, you're warned to export your keys if you want to maintain the logs from any encrypted conversations.
What they are most likely doing is encrypting their database transparently, so that if someone breaks in and just dump the database, nothing worth would have been stolen.
This is typical, and often required by different regulation bodies when you deal with personally identifiable information (PII).
An admin cannot change a user's password.
You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.
Also I'm pretty sure a Slack admin can change a user's email address, at which point they can trigger a password reset.
The reality is that IT administrators are the root of trust at all organizations. This new feature doesn't change that.
Is this true?
It’s of course possible to limit administrators’ access to certain systems, but ultimately the mechanisms to do so are themselves probably set up by your IT administrators in the first place, so in that sense they’re still the root of trust.