Can the managed account actually access files from the unmanaged account or control which processes are active while the unmanaged account runs?
Because, if yes, this absolutely does sound like a security hole:
1) Set up an organisation and add a managed account. Set up policies that install a backdoor on first login.
2) Get hold of victim's Chromebook.
3) Log into the Chromebook using the account from (1)
4) Chromebook will execute the policies and run the backdoor.
5) Use the backdoor to snoop victim's files.
You've successfully gained access to the victim's files without knowing their password. Profit!
This would work even if the victim is fully aware of the issue and never intended to mix managed and unmanaged accounts on their own.