Say who may run what, as whom, and whether they need a password. Get a sudoers.d drop-in and the visudo commands that stop a typo from locking you out of sudo.
A syntax error in sudoers can disable sudo for everyone, and if root has no password you then need a rescue boot to fix it. visudo checks the file before saving it. Put your rules in a drop-in under /etc/sudoers.d instead of editing the main file, so package updates do not conflict with them. Name the file carefully: sudo silently skips any file there whose name contains a dot or ends with a tilde, so admins.conf is ignored while admins works.
This sudoers builder writes rules in the standard who, where, as whom, what format: a user or %group, the host field, the run-as user and group, an optional NOPASSWD tag, and either ALL or a list of commands with absolute paths. It warns about commands that hand out a root shell by accident, such as editors, pagers, and find, suggests sudoedit for file editing, and wraps everything in the visudo commands that validate the file and set its 0440 permissions.
sudo matches the command path exactly. A bare name like systemctl is a syntax error in sudoers, and allowing a relative path would let a user put their own program earlier in PATH. Run command -v systemctl to find the real path.
For a narrow command list, such as one service restart for a deploy user, it is reasonable. For ALL it means anyone who gets that account, through a stolen SSH key or a compromised process, becomes root instantly with no second barrier.
Many programs can start a shell: vim with :!sh, less with !sh, find with -exec. Running them as root hands out a root shell. To let someone edit a root-owned file, allow sudoedit /path/to/file instead, which edits a temporary copy with the user's own editor and permissions.
sudo -l -U username, run as an admin, lists the rules that apply to that user. Users can check their own with sudo -l.