It's my understanding that currently there is no 'Tenant' level administrator, only Account level.
Use case:
1 account/controlplane
2 teams
Goal would be to allow team A and team B to each deploy/manage/configure/etc. their own clusters/nodes/etc. -- but NOT be able to affect each other. i.e. Team A admin should not necessarily have full admin rights over Team B's cluster/nodes.