I think policies are additive.
I found another place where that is indicated:
> ONTAP REST also allows users to add new DACLs/SACLs permissions to an existing already created NTFS through a simple patch call.
https://netapp.io/2021/06/28/simplified-management-of-file-security-permissions-with-ontap-rest-apis/
Incidentally, the same post also indicates that the CLI/API approach should help shorten the time required to apply new permissions:
> The file-directory command allows IT administrators to apply security over large directories without causing significant performance degradation.
I haven't tried to use it, so I'd test with ONTAP Simulator or using a test share. Or maybe just wait until someone who's used it confirms for us.