The permissions we just select can now be configured in each workflow state. On the list of state at the bottom of the workflow main page, select the draft state and adjust the permissions as illustrated on the first illustration above. They establish that only a manager and an owner can look at a thread and make changes to it.
Make sure to always uncheck the top checkboxes "Acquire permission settings". When checked, the security configuration will be inherited from the parent object.
At this point it is important to remember that the Owner role is automatically granted to the user who created the thread.
Then go back to the States section, select the public state and adjust the permission mappings according to the second illustration above.
In this state, Authors can "Add portal content" meaning they can add Discussion Post objects to a Discussion Thread object.
Adjust the permission mappings for the sticky state the same way you did for the public state.
Since the Discussion Thread Module Portal Type has a role mapping giving Author role to the forum/user function category, this means that forum users can post replies to public threads.
Notice that Auditors, which are mapped to forum/visitors don't have that permission, and so they can't post replies in this configuration.