Hi all,
I have a CRM system which deals with much of the 'Service' area i.e. cases and queues. We have the following hierarchy

Each set of initials represent a business unit. When I place a new user in the 'AC' business unit and give them a role, I expect them only to see cases which are owned by users and/or teams from the 'AC business unit and below (AP and AR). This is because I am giving them a role with a security permissions of Parent:Child Read on the case entity meaning they should only see cases from AC, AP and AR.
However they are seeing cases owned by all teams and users across the board. e.g. I have an admin user sitting in Business Unit 'CRM' at the top. When they create a case, users in 'AC', 'PR' and 'RC' can see it, DESPITE only having Parent:Child Read access.
- Parent: Child Business Unit — Privileges for all records owned in the business unit to which the user belongs and to all the child business units subordinate to that business unit
By this definition, if the admin in the top business unit creates a case, then this shouldnt be seen by those in subordinate business units (unless they have organisational read access).
The cases havent been shared with the default teams of the business units either.
Any advice is appreciated - thanks