In the workspace a user created a private repo under a private project even though he doesn't belong to any of the user groups or direct access to the project. The user belong to a different user group which isn't associated with any project or repo. Interestingly He cannot see other repos of the project but can create a repo under the project.
How to restrict that?