# chainctl policies override create

URL: https://edu.chainguard.dev/platform/chainctl/chainctl-docs/chainctl_policies_override_create.md
Last Modified: July 22, 2026
Tags: chainctl, Reference, Product

 chainctl policies override create Create a policy override.
Synopsis Create an override that waives a policy for one specific image.
The override flips the policy&rsquo;s result to ALLOWED for the image identified by &ndash;digest (a manifest digest), under the policy named by &ndash;policy. A &ndash;reason is required to record why the waiver was granted.
Creating an override requires the policies.override.create capability, a separate capability typically held by organization owners.
chainctl policies override create --policy POLICY --digest DIGEST --reason REASON [--parent ORG] [--output=json|table] [flags] Examples # Waive the no-eol policy for a specific image digest chainctl policies override create --policy=no-eol --parent=engineering \ --digest=sha256:abc123... --reason=&#34;approved exception, ticket OPS-42&#34; Options --digest string The image manifest digest to waive (e.g. sha256:abc...). --parent string The name or id of the organization to scope the override to. --policy string The name or UIDP of the policy to override. --reason string The justification for the override. Options inherited from parent commands --api string The url of the Chainguard platform API. (default &#34;https://console-api.enforce.dev&#34;) --audience string The Chainguard token audience to request. (default &#34;https://console-api.enforce.dev&#34;) --config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly. --console string The url of the Chainguard platform Console. (default &#34;https://console.chainguard.dev&#34;) --force-color Force color output even when stdout is not a TTY. -h, --help Help for chainctl --issuer string The url of the Chainguard STS endpoint. (default &#34;https://issuer.enforce.dev&#34;) --log-level string Set the log level (debug, info) (default &#34;ERROR&#34;) -o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide] -v, --v int Set the log verbosity level. SEE ALSO chainctl policies override	- Manage policy overrides. 
