OK, this makes perfect sense and thanks very much for pointing me to the right thread.

...but...

I swear I saw somewhere in the documentation these files needed to be 644, or perhaps it was in an area stipulating methods for securing the site?

I simply cannot ask my client to reset permissions on files every time he wants to edit them, any ideas on a way around this? (I only ask because I'm led to believe the very nature of these files being editable makes them the most likely to be hacked)