Published
Last reviewed: 2026-07-25
Policy onboarding
Set CodeCleared license, quality, and Dependency Advisor policies before your team relies on scan results.
Purpose
Policy onboarding sets the decisions against which future scans are evaluated.
Who
Organization owners and admins.
Prerequisites
Connect at least one repository and know the organization’s approved license and quality posture.
How it works
- Configure license policy.
- Configure quality gates (quality rules).
- Configure Dependency Advisor choices. If category governance has no rules yet, run a stack trends report and choose which libraries to allow.
- Run a scan and review behavior against the policies.
Business rules
Policy changes apply at the organization level. Leaving onboarding midway saves only the policies already completed; it does not create an all-or-nothing draft.
Scenarios & edge cases
Unexpected result: confirm which policy stages were completed. Different teams need different rules: use the supported policy scope rather than informal exceptions.
Limits
Policies guide results; they do not automatically approve a release.
Common errors
- Assuming skipped onboarding steps are configured.
- Editing a policy without reviewing affected scans.