Skip to content
Published

Last reviewed: 2026-07-25

Policy onboarding

Set CodeCleared license, quality, and Dependency Advisor policies before your team relies on scan results.

Purpose

Policy onboarding sets the decisions against which future scans are evaluated.

Who

Organization owners and admins.

Prerequisites

Connect at least one repository and know the organization’s approved license and quality posture.

How it works

  1. Configure license policy.
  2. Configure quality gates (quality rules).
  3. Configure Dependency Advisor choices. If category governance has no rules yet, run a stack trends report and choose which libraries to allow.
  4. Run a scan and review behavior against the policies.

Business rules

Policy changes apply at the organization level. Leaving onboarding midway saves only the policies already completed; it does not create an all-or-nothing draft.

Scenarios & edge cases

Unexpected result: confirm which policy stages were completed. Different teams need different rules: use the supported policy scope rather than informal exceptions.

Limits

Policies guide results; they do not automatically approve a release.

Common errors

  • Assuming skipped onboarding steps are configured.
  • Editing a policy without reviewing affected scans.

Links