It's pretty easy to scrape your own calendar events in Meta. I'm not sure about others' as I'm not a manager, but I wouldn't be surprised if it were visible as long as someone is in your report chain.
(I work at Meta)
(I work at Meta)
The only report chain based permissions were around distribution lists which were just some powershell scripts that walked AD every night. These also got used for security groups to gate access to some things. Be default, calendars were visible to all authenticated users unless you made them private or individual events private. The meeting tool leveraged this for example.
I was working on corp email (among other things) there from 2009 to 2016, so I can't speak for now.