I presume then I have to copy these 'permissions' down to the App database at some stage.. is this correct and if so, whats the easiest way of doing this ?
Yep, you need to deploy the data you added through the security editor and... the easiest way is with the DDT, since it will create a Deployment Package for you.