To further elaborate, permissions changes made in the "Manage Apps" page are not being propagated through the Search Head Cluster. However, permissions changes made on individual Knowledge Objects are propagating successfully.
The above information is only true for SPlunk version 6.3 and above. For splunk 6.2 had a Bug :: SPL-99457:[SHPNEXT] allow permissions on app containers to be edited via UI, and replicate them.
The gist is that app permissions only affect knowledge objects, whereas other app values (like enable/disable) affect system configurations. Currently we only replicate user-level stuff other system stuff should come from the deployer