Limited-scope user has access to modules outside of Role-defined limits

We setup our WAS security personnel with permissions limiting them to WAS and Reporting from within Role Management over a year ago. However, during a recent audit, we found that these users actually have access to all of the modules we've licensed, and the ONLY limit on anything is the Tag set they can view - this isn't good.


What's the trick to getting a user's wild access under control?