We upgraded to 13.3 about two months ago and recently ran across an issue. We discovered that people who initiate processes can see the process in their Action Items portlet on the Organizer, even if the person is not actually assigned as an approver for that process. If that weren't bad enough, they can also EDIT the action item using the drop down menu and change the status to Approved, Rejected, etc. If you click the link in the Action Items portlet to open the process and look at the details you can confirm that the initiator is NOT a current assignee. And on this detail page it does not look like they have edit capabilities. But the fact that this access appears to be granted at the portlet page is alarming, not to mention that the action item shouldn't even be in that person's action item list to start with if they aren't an assignee.
Can anyone else confirm this issue? I've looked through our access rights and don't see anything out of order. Our project managers only have the ability to Start processes or View Definition. I'm not sure what else to check. I've opened a case with CA but thought I'd also poll the community to see if anyone else has run across this.