I want to restrict access to a specific issue type "Meta" for users that are part of a specific group "VCS". In setting>issue types it should be possible to do this:

Now, a user Adam in group VCS, should not be able to see newly created issues of type "Meta" since VCS has been assigned role "Member".
However, Adam can see newly created "Meta" issues, even though that user shouldn't be able to do that.
Why? Am I doing something wrong...? Any suggestions are deeply appreciated!
---
The user Adam is in group VCS and in no other groups and has a role "basic" on the user detail's page.
The user Adam has not been invited to the project individually. Adams access to the project is set by the group VCS.
The group VCS has been assigned role "Member".
/J