Hierarchal Permission File for RLS

Hello,

I am reading/following the blog, Implement row-level security using a complete LDAP hierarchical organization structure in Amazon QuickSight to gain more understanding about how this security can be implemented within QS. The guide is successful in achieving restricting data, but I was a bit confused on the permissions file. Would anyone be able to elaborate on how the permission file is structured and how/why it works?

Thank you