Nevertheless this settings is not entirely correct as well - the default action for non-matching events is to deny create, update and delete. So you have to explicitely allow update for normal user.
Anyway, With this settings you shouldn’t be able to do anything with a normal user.
Please can you attach screenshots of related screen-fragments (both rules)?