Permissions are grouped into four main categories:

Application. Everything to do with Client and Admin Console.
Confidential Information. These options include edit and mask (hide) settings for such information as bank account numbers, social security numbers, etc.
Object. These are automated processes such as work flows and execution plans. If these are turned off, any step requiring a user intervention will not work. Since the default for these is off, they should be turned on.
Reports. Access to specific reports can be limited to groups. These permissions control who can delete, modify. and upload report definitions and who can view the SQL for a report.
Each of these categories is further divided into subcategories.
For example, Applications has a sub-category named CostGuard Client, which is further subdivided into Customer Management, Accounts Receivable Management, and so on.
Permission Colors
Enabled permissions are green.
For a permission to be enabled, all nodes in the path must be enabled.
Disabled permissions are red.
Note
If a permission is prefaced by Deny, enabling that permission denies access to the related functionality. For example, if you enable Deny under Admin Console > Security, the Security node for users assigned to that profile is not displayed when they access Admin Console.

Note
If you are assigned to two different profiles with overlapping permissions -- and the same permission is enabled in one but disabled in the other -- the enabled permission will override the disabled permission.