I recognized a strange behavior in authorization diagram (MEGA 2009SP5 CP7) when I disconnect a user from a authorization zone or when I connect a user to another authorization zone. He doesn't disappear from the previous authorization. So in this case the user is placed in both authorization zones. Does anyone has the same strange behavior?
I did not reproduce your concern on a brand new environment as soon as I connect my user to a authorization level it is disconnected from the previous level, on the authorization diagram and on the explorer. The user therefore cannot be in two authorizations level.
I reproduce the behavior in my demo environment that I agree is strange !