The vtiger history which it has a bug in it. If a user applies the history widget on the vtiger dashboard homepage, the user is able to see any activities in the system and any updates in the system even though they might not have permissions to see them. It's basically a complete hole in the permission system with vtiger.
Another bug is with email and vtiger. Users are able to see any email regardless of permissions. So if they can get to a contact on an organization that they have permission to access, they can see all emails regardless if they have been restricted. if they have access to the mail manager they can see all emails as well.
I hope these are fixed in the next release.
Pat OBrien
Boru Apps
www.boruapps.com