@babk821293, Have a look at this community post on the type of access granted when you use an organizational unit. If the user is in any security group (standard/admin) with all assigned, he will have access to anything in the whole system. I would suggest setup a separate custom security group and assigning an org unit to control the object access.
Thanks, Sathees