Because they start as a list. Somebody is granted access for a project, changes team, and the old access is never removed because removing it was nobody's job.
Two years later nobody can say who can see margin, and finding out means reading a list that no longer reflects anything.
Role decides what kind of thing someone can do. Team decides whose records they see. Record level handles the exceptions — a deal one person owns that others should not open.
Most companies need all three and configure only the first, which is why they end up with everyone able to see everything.
Usually yes within a team, and usually not the margin. That is a field decision rather than a record one.
Derive access from reporting lines and it follows automatically. Maintaining a list guarantees drift.
They must. A token should read exactly what its user could.
Half an hour with your own data usually saves reading three of these. The guides will still be here afterwards.