The kernel decides every access by number, UID and GID. /etc/passwd (world-readable) holds seven fields per account: name, x, UID, primary GID, comment, home and shell. Password hashes live in /etc/shadow (mode 640), where ! or * means no password can ever match. /etc/group lists only supplementary members; the primary group is recorded in /etc/passwd. People get UIDs 1000 to 60000 (UID_MIN, UID_MAX in /etc/login.defs); system accounts such as www-data sit below and use /usr/sbin/nologin as their shell. Any second UID 0 account is a second root. Query with getent, which also consults LDAP or SSSD, rather than grep.
id; id www-data # your identity, then the one Apache and PHP-FPM use
getent passwd | awk -F: '$3 == 0 {print $1}' # every UID 0 account
getent passwd | awk -F: '$3 >= 1000 && $3 < 60000 {print $1, $3}' # human accountsOutput
uid=1000(dev) gid=1000(dev) groups=1000(dev),27(sudo) uid=33(www-data) gid=33(www-data) groups=33(www-data) root dev 1000