When ESXi role privileges are updated, they do not persist after ESXi reboot. ESXi fails to save updates to persistent storage.
The issue is limited to modification of existing roles. Privileges granted during role creation remain after reboot.
A known bug occurs where ESXi does not save the most recent group permissions change that occurred before the reboot.
This issue has been resolved in 8.0U3.
Updated privileges can be saved by creating a dummy role and then applying it to the user group, only to remove it.