This question relates to Jira Cloud.
There is a map graphic in the documentation "Jira Permissions Made Simple" that shows a one-to-one relationship between a Project Role and a Permission Scheme; there is also a one-to-one relationship between a Project and a Permission Scheme: a project can have only one Permission Scheme.
When setting up "External Users", like customers, in order to limit their access, you are required to link a Project Role, "Customers", to a different Permissions Scheme and remove them from "jira-software-users". That approach seems to suggest that a custom Project Role points to the custom Permission Scheme and not the Permission Scheme associated with the project. This seems to contradict the map in "Jira Permissions Made Simple" I reference above.
What am I missing? What is the relationship between Users, Groups, Project Roles, and Permissions?