I thought that he added his public key to the Rails user through his own account settings, which wouldn't give him access to the Rails web admin.
This bug allowed one to add their public key to another user's account, and make changes to comments and issues.