Files and folders are set with POSIX permissions and, if enabled on the volume, can also have File Access Control Lists applied inidividually.
(Both are configured in WGM -> Sharing)
File ACLs, which can be set in a granular way, override any POSIX permissions which they related to (on a permission-by-permisison basis). You can use the Effective Permissions Inspector (in WGM utility menu) to see how the ACL will affect or override the POSIX permissions for any particular use or group.
A user logged in over AFP can change permissions or ownership of a file they own IF there is no corresponding ACL list which prevents this (an ACL can be setup to deny Change Permissions or Change Owner).
A user logged in over AFP cannot change the ACL entry, however, that applies to a given file or folder.