Yup, you're right, although from the sudoers file you can add specific commands the user can run with sudo, limiting all others.
Not to mention the person would still need his password to execute via sudo, which no-one else should really have, and if they do surely you trust them not to go screwing with your system
