Skip to content
Published

Last reviewed: 2026-07-27

Policy bundles

Import and export Team and Regulated policy bundles to migrate reviewed rules between organizations without applying unreviewed changes.

Move policies with a review step

Policy bundle import and export are available on Team and Regulated plans. Use a bundle to move policy configuration between organizations or environments while keeping the change reviewable. The same Public API surface is available to MCP clients via export_policy_bundle, validate_policy_bundle, and import_policy_bundle (scopes policy:read / policy:write).

Schema version: export and import use apiVersion: codecleared.io/policy/1.1.0 (default). Quality rules may use shorthand conditions or expressions (+ match: all|any). codecleared.io/policy/1.0.0 is sunset and rejected on import.

Safe migration workflow

  1. Export the source organization’s intended policies (for Quality Gates, use kind=quality).
  2. Version the bundle in your approved configuration process.
  3. Review its rules and overrides against the destination organization’s needs.
  4. Import into the destination and verify the resulting active policies.
  5. Re-run representative checks before relying on the migrated policy.

Avoid accidental broadening

Policies and exceptions may have different consequences in another organization. Do not apply a bundle unreviewed, overwrite local decisions without approval, or assume the source organization’s exceptions are valid for a client destination. Use audit logs to retain the change trail.

Related documentation