Preventing Users able to change their Role in My Profile

I am sure I am doing something wrong, however it seems that unless I limit my users to READ ONLY access versus EDIT or DELETE they can modify their profile and change their Role to what ever they want. I only want users that are in the ADMIN Role only to be able to change user roles.
P.S. I have been using Xataface for a week now and I am amazed with the application. Still a lot to learn but it is a great application. Thank you for creating it.
P.S. I have been using Xataface for a week now and I am amazed with the application. Still a lot to learn but it is a great application. Thank you for creating it.