Hi
The notion of workflow is not taken into account. Indeed, a user having access to a limited number of statuses by combining a role and a tracker see all the statuses.
In this case, a client connected with his account see all the statuses even those reserved for the dev team
Regards