The three roles
Members do the work: create and edit tasks, create and edit projects, plan their week. Admins do that and set the place up: invite and remove people, change roles, define statuses and custom fields, rename and delete projects. The owner does everything an admin does, and alone can transfer ownership, delete the workspace and handle billing.
Settings, Roles renders the full matrix. It is generated from the same rules the product enforces, so it cannot drift from what actually happens.
Exactly one owner
A workspace has one owner and always has one. Ownership is not assigned like a role, it is transferred: the workspace changes hands, the new owner is promoted and the previous owner becomes an admin, all at once. There is no window in which the workspace has two owners or none.
Transferring is the owner's action alone. If you are the only person in a workspace there is nobody to transfer to, which is worth remembering before you delete an account you still need.
The interface is a courtesy, the rules are the boundary
Cretask hides what your role cannot do, but hiding a button is not security. Every capability is enforced on the server as well, so a request that skips the interface is refused the same way.
While your role is still loading, the interface assumes you can do nothing and shows the member's view. That is why an admin sometimes sees controls appear a moment after a page opens, rather than seeing controls that turn out not to work.
People and Members are different pages
People is the directory: who is here, what they are carrying, and a page per person. Members, under Settings, is access management: roles, removal, transfer and revoking invitations.
Invitations you have received, and leaving a workspace, are personal rather than shared, so they live under Settings, Workspaces with the rest of your account.