GoDawgs,
The recommendations from HP are: 1) to only have users be a member of one group (to insure permissions are applied appropriately and not incorrectly cross assigned as can and does sometimes happen when a user is the member of more than one group) and 2) to always create a custom user group off of the default TDADMIN group only and remove permissions to obtain the desired users permissions.
(**Note: Creating a custom group off of any other group has been proven that it can create issues with the association of permissions, as for some reason adding permissions to lower groups and creating from groups other than the default TDADMIN group doesn't always yield the desired results. In theory it makes little difference but in practice it can and has in real world usage caused undesired results for the newly created group which can be near impossible to troubleshoot the root cause).
Hope this helps,
Dan