I don't think that's true. In the corporate world, Slack is authenticated with AD/SAML/etc. and Slack has no idea who is changing passwords on that backend system.
The reality is that IT administrators are the root of trust at all organizations. This new feature doesn't change that.