“Do they have access” is one thing, but what happens when they use the access? Is there any logging or proactive monitoring?
A single support account reading say 10x the normal number of accounts per day, with a different geographic distribution than the norm, should ring alarm bells. It’s not enough to say “well shucks they have access to the data, guess we’ll do nothing”