The docs were inconsistent between readwrite and readonly, the policy itself evaluates to a readwrite policy, so the inconsistency is solved by changing the odd occurrence of readonly.