Last reviewed: 2026-07-29
Policy overrides
Record narrow, auditable license honors, overrides, scoped allowances, and dependency ignores in CodeCleared.
Purpose
Governance decisions on licenses and dependencies stay auditable. They are not finding triage (SCA CVE, secrets, or SAST ignores).
Three license levers coexist:
| Lever | Effect | Mutates |
|---|---|---|
| Override / Honor | Corrects the license string evaluated for a package, then re-checks org policy | license_overrides / license_honors |
| Scoped allowance | Marks a license or package compliant in a project unit, repository, or (package only) organization | license_allowances |
| Append to whitelist | Adds a license id to an org whitelist policy (everywhere) | license_policies |
Who
- Triage+: honor/override; allow license or package at project unit or repository; remove those allowances.
- Admin / owner: allow package organization-wide; append licenses to a whitelist policy; manage all allowances in Settings.
- Members / viewers: cannot write these decisions.
Service tokens: policy:read lists; policy:write creates/deletes PU/repo allowances and overrides (minting triage+); policy:admin for org package allowances and whitelist append (minting admin+). These scopes are not implied by scan:all.
Prerequisites
Choose the narrowest scope that solves the business case. A paid commercial license for one repo is a package@repository allowance with a required reason—not an org-wide whitelist change.
How it works
- From a non-compliant license finding, use Override to fix the evaluated string, or the chevron menu for allowances / whitelist append.
- Allowances require a non-blank reason (like finding ignores).
- Live license status and scores refresh without consuming scan credits. Persisted scan results and PR check history refresh on the next natural license scan—saving an allowance does not start a scan.
Evaluation order (first match wins): package@PU → package@repo → package@org → license@PU → license@repo → then honor/override → policies.
license×organization is not an allowance; use append-to-whitelist.
Business rules
Allowances and overrides can emit governance/SLA updates (finding.governance.excepted where applicable). Prefer project-unit scope when other units in the same repository must stay strict. Do not use license governance to silence a vulnerability, secret, or SAST finding.
Surfaces
- App: project unit Licenses tab, repository allowances panel, Settings → license allowances / policies.
- Public API
/api/v1:license-allowances,license-overrides,POST /license-policies/:id/licenses. - MCP:
codecleared_*_license_allowance*,*_license_override*,codecleared_append_license_policy_licenses.
Common errors
- Using override when the license string is correct but the package needs a scoped exemption (use an allowance).
- Creating an org-wide package allowance when a repository or project-unit scope would suffice.
- Expecting PR checks / stored ScanResult to update before the next license scan.