It's actually possible to grant users fine-grained access to specific root-owned files/directories. Read up on Linux ACLs.

It's also possible to grant access to certain tasks that require root...