Signed transactions can even be shared through other channels, to be broadcast at a later time for settlement, like a check. This is how the Lightning Network functions.
Keys can be held in many forms, including purely in software, digitally inside a hardware secure element, or converted to words and printed on paper or metal.
Bitcoin even has basic scripting that allows more complex setups, such as only allowing a ledger entry to be updated after a certain duration (timelocks) or requiring a quorum of signers (multisig), so simply having a corresponding private is not always sufficient to immediately spend the corresponding funds.
In the past “brain wallets” were popular, where the private key is generated from a memorized passphrase. These are a bad idea because it’s trivial to watch addresses corresponding to every entry a password dump, and automatically move these funds whether you’re the original owner or not. I mention this to illustrate how having the corresponding private key is necessary to control funds but it’s not sufficient to prevent someone else from controlling the same funds.
On top of all this, most “Bitcoin users” leave “their” Bitcoin on exchanges, so what they really own are IOUs rather than Bitcoin itself.
Bitcoin “ownership” can be pretty abstract.