Why are the users able to see the measures even though there is no permission to access them?

Why are the users able to see the measures even though there is no permission to access them?

All the security privileges assigned to a ROLE can be accessed by the Users under the corresponding ROLE provided nothing is specifically assigned at the USER level. On the other hand, if there are specific privileges assigned to individual USERS then, the privileges assigned at the ROLE level will be over-ridden. Therefore, a specific user might be able to see the measures even though there is no permission to access the measures, because the ROLE to which the user belongs has the privilege.