One or more groups, each pairing a set of file patterns with the substitutions that apply only to those files.

Grouping exists so that XML paths are never applied to JSON files and vice versa. In Version 1.0 a given file must be matched by exactly one group; overlapping groups are rejected during validation, before any file is read or any credential resolved.