As a database consultant I can assure you there are great many servers on which I have a user, but no ability to "su root".
When you have DBA access to production databases, lack of root does not stand in the way of doing evil.
It does stand in the way of using message logs to troubleshoot, checking contents of /proc to determine which directory a process is running from, tuning TCP parameters to maximize data transfer rates without nagging the sysadmins, etc.
(For evil-genius-DBA's bonus points for doing that via the database instead of the shell and censoring traces from the db logs too...)