Hi Tim,
nope, you are not missing anything I think.
The FortiAuthenticator (FAC hereinafter) admins can be profiled so each 'role' can do certain things, but generally on whole FAC.
There is nothing like VDOMs known from FortiGate or ADOMs from FortiManager.
Usual implementation is one FAC per enterprise where admins are for one subject.
However, if you want give customer ability to manage his users then I do see two possible options:
A) Remote User Sync Rules
this feature allows you to keep admin accounts for you only, no access from customer to FAC, but FAC will sync users from customer's LDAP automatically and according to set filter (just users matching LDAP filter, for example belonging to specific group/OU on LDAP/AD). This will create/remove user on FAC once created/removed in LDAP. Plus, users can be provided with 2FA token when synced, and tokens returned to pool when user get deleted (once he is not seen as matching sync filter).
This feature is used very often in situations where FAC is managed by one group/team of admins but AD/LDAP is managed by another team.
B) Guest portal
on the FAC you can create so called 'sponsor' which is admin able to manage just guest/user accounts on FAC, nothing else.