I have created a Workflow and marked it as a Business Process. I have removed the everyone group from having permissions to it and added a specific user to only have permissions to it. If I then log into the repository as a different user and do a search based on Business Processes, I can see the Business Process in the list.
If my user does not have permissions to Start or View Details of the Business Process in question, why can they see it in the list? It doesn't seem like it respects the permissions set.