He certainly did NOT need this access to administer systems. It still boggles my mind that the sensitive data on those systems was not encrypted so administrators could not read it.
In any well-run IT organization, the DBAs cannot read the credit card numbers stored in the database and the systems administrators cannot read user passwords. But they can still administer the database and the the servers.