There is a dangerous usability bug in the suggestions of the useful user tagging feature.
When it starts to tag someone with “@” a list of users appears, but it’s unfiltered by the users’ rights related to task>project>team.
It means that is too easy to tag someone who is completely external to task>project>team, giving it automatically the right to access the tag, and without any ALERT to the tagger.
I did that too many times that error, overall when I started tagging someone digiting the first name letter, as “@ricc…”.
Please check it.