Each app has pre-defined roles that comprise the above permissions. For example, the Page app may contain a Page Author role with the CRUD permission on that app. This allows the user to manage content but not publish it.