Groups are collections of users which have been assigned to one or more Roles.
When a User is created, it is assigned to a Primary Group, and can subsequently be assigned to one or more Additional Groups. The permissions a User is granted are determined based on all of the Groups of which they are a member - That is to say, a User will inherit the Permissions associated with each Role that has been associated with their Primary Group and any Secondary Group(s) of which they are a member.
There is no concept of "denying" a user or group a particular Permission. A user does not inherit a particular permission unless they are member of a Group which has been associated with a Role which has been granted a particular Permission.
Once a Group has been created, it must be assigned one or more Roles to be functional.
When assigning a Role to a Group, the Role can be applied either "Globally" or "Limited." When a Role is assigned to a Group as Globally,, the members of that Group inherit the Permissions associated with that Role at all locations. When a Role is assigned Limited to a Group, you will select either a Location or a Location Group. When a Role is assigned to a Group as Limited, the members of that Group inherit the Permissions associated with that Role at the specific Location or Location Group.