Skip to content
Published

Last reviewed: 2026-07-29

Policy overrides

Record narrow, auditable license honors, overrides, scoped allowances, and dependency ignores in CodeCleared.

Purpose

Governance decisions on licenses and dependencies stay auditable. They are not finding triage (SCA CVE, secrets, or SAST ignores).

Three license levers coexist:

LeverEffectMutates
Override / HonorCorrects the license string evaluated for a package, then re-checks org policylicense_overrides / license_honors
Scoped allowanceMarks a license or package compliant in a project unit, repository, or (package only) organizationlicense_allowances
Append to whitelistAdds a license id to an org whitelist policy (everywhere)license_policies

Who

  • Triage+: honor/override; allow license or package at project unit or repository; remove those allowances.
  • Admin / owner: allow package organization-wide; append licenses to a whitelist policy; manage all allowances in Settings.
  • Members / viewers: cannot write these decisions.

Service tokens: policy:read lists; policy:write creates/deletes PU/repo allowances and overrides (minting triage+); policy:admin for org package allowances and whitelist append (minting admin+). These scopes are not implied by scan:all.

Prerequisites

Choose the narrowest scope that solves the business case. A paid commercial license for one repo is a package@repository allowance with a required reason—not an org-wide whitelist change.

How it works

  1. From a non-compliant license finding, use Override to fix the evaluated string, or the chevron menu for allowances / whitelist append.
  2. Allowances require a non-blank reason (like finding ignores).
  3. Live license status and scores refresh without consuming scan credits. Persisted scan results and PR check history refresh on the next natural license scan—saving an allowance does not start a scan.

Evaluation order (first match wins): package@PU → package@repo → package@org → license@PU → license@repo → then honor/override → policies.

license×organization is not an allowance; use append-to-whitelist.

Business rules

Allowances and overrides can emit governance/SLA updates (finding.governance.excepted where applicable). Prefer project-unit scope when other units in the same repository must stay strict. Do not use license governance to silence a vulnerability, secret, or SAST finding.

Surfaces

  • App: project unit Licenses tab, repository allowances panel, Settings → license allowances / policies.
  • Public API /api/v1: license-allowances, license-overrides, POST /license-policies/:id/licenses.
  • MCP: codecleared_*_license_allowance*, *_license_override*, codecleared_append_license_policy_licenses.

Common errors

  • Using override when the license string is correct but the package needs a scoped exemption (use an allowance).
  • Creating an org-wide package allowance when a repository or project-unit scope would suffice.
  • Expecting PR checks / stored ScanResult to update before the next license scan.

Links