...much has to modify /etc/passwd, master.passwd and group, to create user accounts. Most users (including root) are expected to edit .cshrc or .shrc to their taste. The IDS functionality really should ignore those changes.
On the other hand, the fact that permissions/ownership for /root...