As a company we recently changed to an Enterprise Plan. During our onboarding we went through the usual questions - what restrictions should be put in place, what should the new structure look like, how can we prevent boards with the same name or similar names to be created etc. So we decided that projects created within a team have to be visible to all team members.
After about a week, we discovered that while the Board settings showed that only certain people had access to the board, the settings we had placed on the projects overruled the board settings. This isn’t visible when looking at the board settings and I don’t think that it is made clear enough on the project settings. Or rather, one should be able to make a project visible but still restrict the boards within the project. Not being able to do so creates massive confidentiality and security breaches.