Hi,
First of all, in case you are using the 2.1.1 version, you should upgrade to 2.1.2 as soon (see release history for more information) and see if it changes something.
Could you clarify what you mean by website admin accounts? Site collection owner or accounts that have full control over the web site?
What exactly do you mean by "adding full control permissions to your users"? By putting them into some group? On which site? Do the sub-sites inherit from parent permissions?
I can't say what's wrong but here is the tests I would surely do:
I would try to confirm that Windows Integrated security works as expected. I would run a non rollup report set up with Windows Integrated security using an account that has access to a subset of the list involved in the report. The report should display the subset data only. For the sake of completeness, I would run the same report again using an account that has full permission to the list.
I would try to see if a user that can't currently run the rollup report is able to execute the rollup report when having enough permissions. To make it simple, I would temporarily set the user accound as a secondary owner for the site collection and will run the rollup report again. That would be really surprising if with such permissions he still can't run the report considering that you seem to have users account that are already able to run it.
If after those previous tests, I still can't really get where things are going wrong, I would try to set up a small sample report in a test site collection with only one subsite and verify that things are working as expected when setting the appropriate permissions.
Let me know.
Regards,