Security settings vs realtime tag provider settings

Copy, I believe this security is set up correctly, as seen in this image

My ultimate goal is to get it so a an approved role from this security zone can write to tags, but in trouble shooting I found the approved role worked, but once adding the security zone, I lost all functionality.

I know the security provider is set up correctly, because when I change permissions on the security zone i.e. read, read/write, read write edit, this changes what can be done from the remote gateway.

The trouble comes when I try to implement the security zone on a tag or tag provider, I loose all functionality from the remote gateway.