I have only guess work here.
You might have done this. Verify if there’s any extra security role that test account user is having.
Go to App, click the ellipses & Manage roles. See the security role you mapped there.
Check the users Business unit of it differs. Also any team membership & security role for teams?
Finally take the app url with querystring appId & hit directly in incognito browser with that troublesome user.