The OpenCode config file policy rules are compiled into. OpenCode loads
.opencode/opencode.json after the project’s opencode.json and applies
the last permission rule that matches, so rules here take precedence over
the project’s own.
The OpenCode rules one policy rule compiles to, as Tuff records them: a
permission name, then a space and a pattern when the rule sits in that
permission’s object. The effect is the action the rule is written with.