I've distilled this to quite a simple case, in an on-demand instance.
I'm using a slightly modified copy of the default Permission Scheme (I've added to it, not removed). The steps below are what I took after permissions didn't work as expected.
In my example the user Fred is a member of the developers, users and (a new custom) Team group.
In project roles, I started with no users or groups in the roles and then added the Team group to the developer and user role.
But this didn't give Fred any access to the project issues. He could see the project, but no issues.
Then I directly added Fred to those roles. No change.
Next, I added the developer group to the developer role, and the user group to the user role. Still nothing.
So I removed the Team group from the Project Roles - no change.
Then I removed Fred user from its direct inclusion in project roles - and bingo, it works.
This seems to indicate that granting access by either a user or custom group doesn't work and that there are issues with combinations.
Am I misinterpreting something or is there an issue to avoid?
Brendan