A Jira permission scheme is just a reusable list of 'who can do what,' attached to one or more projects. Most permission confusion traces to a single setting — the Browse Projects permission granted to 'Any logged-in user' — which quietly lets everyone in your instance see a project. Understand roles vs groups, fix that one default, and permission schemes stop being scary.
Jira Cloud has no guest role. Every account that can see a project consumes a licensed seat, with one narrow exception (the Jira Service Management customer portal). Everything else people call 'guest access' is one of three workarounds: automation emails, anonymous public access, or a sharing app. Which you want depends on whether your guest needs to work in the project or just see it.