I have a problem that the user has more rights than the security role provides.
I assigned him a child business unit and security role for him.
Everything worked fine. But suddenly I saw that the user sees all apps (for all business units, not just for his).
I checked the access level for viewing applications - everything is right - for his role he need to see only 1 app.
But in reality it is not.
When i assigned him a child business unit and security role for him - he can see other applications and even customize
the system!!!
it's incredible, because his role does not give him such rights and there is only one role assigned to him.
I tried to assign a parent business unit to him and everything began to work as it should.
how can it be that a child unit gives more rights than a parent?
or the problem is something else?