One or more groups, each pairing a set of file patterns with the substitutions that apply only to those files.

Grouping exists so that XML paths are never applied to JSON files and vice versa. A given file must be matched by exactly one group; overlapping groups are rejected during file discovery, before any file is read or modified.

Credentials are resolved before that, on the controller, so a run that fails because two groups claim the same file has already looked up and resolved the credentials it was configured with.