
Role based viewing and editing restrictions simple do not work.
So you have a "Staff" role that can supposedly view and edit a "Customer" profile with notes about there customers. You don't give your customers view or edit permissions on the customer profile for obvious reasons.
When you find out that your customers can still see all the crap you've written about them and all the sensitive data you've posted, you've got a serious problem. Do not under any circumstances install this module if you value privacy!
Review by mrphilbert [info] on April 2, 2011 - 22:05