
Explanation
Box 1: Microsoft Teams team
Dataverse supports two types of record ownership. Organization owned, and User or Team owned. This is a choice that happens at the time the table is created and can't be changed. For security purposes, records that are organization owned, the only access level choices is either the user can do the operation or can't.
For user and team owned records, the access level choices for most privileges are tiered Organization, Business Unit, Business Unit and Child Business Unit or only the user's own records. That means for read privilege on contact, I could set user owned, and the user would only see their own records.
Box 2: Access team
An access team doesn't own records and doesn't have security roles assigned to the team. The team members have privileges defined by their individual security roles and by roles from the teams in which they are members. The records are shared with an access team and the team is granted access rights on the records, such as Read, Write or Append.
Reference:
https://docs.microsoft.com/en-us/power-platform/admin/wp-security-cds
https://docs.microsoft.com/en-us/powerapps/developer/data-platform/use-access-teams-owner-teams-collaborate