@nickdsl This is a known limitation: at the moment, xo-server doesn’t filter objects based on permissions: permissions are currently applied during actions.
We’re actively working on resolving this in XO6 and the new REST API to improve overall functionality.