(1) Which permissions are needed and why?
The low priority status bar notification shows the number of pending operations, which can be:
(3) What is a valid security certificate?
Valid security certificates are officially signed (not self signed) and have matching a host name.
(4) Why is IMAP IDLE required?
Without IMAP IDLE emails need to be periodically fetched, which is a waste of battery power and internet bandwidth and will delay notification of new emails.
If you have another question, you can use this forum.