It is supposed to be that way. It is a Homedirectory. Here a user can store/save the 'private' data that should not be shared with anyone.
All serversystems (Windows, Novell, Linux) have this security system.
Using the serverconsole you can have access to all the directories when you login as root.