Bitcoin coins aren't "owned"; they're locked by a script. To spend one you supply an unlocking script; glue it in front of the lock, run the pair on a stack machine, and if the stack ends holding true, the money moves. Step through four classic locks below.
The scriptPubKey ships with the coin; the scriptSig is provided by the spender later. Spending is just: can you write a prefix that makes the whole thing pass?
Script has no jumps or loops, so every program halts. That keeps validation cheap and predictable: nodes can't be tricked into running forever.
The same opcodes express a plain payment, an m-of-n vault, a hash-revealed payment and a time-delayed one. Lightning channels are built from exactly these pieces.