Sounds like authentication is working great, but their authorization design may be flawed.
How is it flawed? That is the nature of crowdsourcing.