# chainctl policies override create

URL: https://deploy-preview-3613--ornate-narwhal-088216.netlify.app/platform/chainctl/chainctl-docs/chainctl_policies_override_create.md
Last Modified: July 31, 2026
Tags: chainctl, Reference, Product

 chainctl policies override create Create a policy override.
Synopsis Create an override that waives a policy for one specific image.
The override flips the policy&rsquo;s result to ALLOWED for the image identified by &ndash;digest — a sha256 digest written as sha256: followed by exactly 64 lowercase hex characters — under the policy named by &ndash;policy. A tag or a non-sha256 value is rejected locally before any API call. A &ndash;reason is required to record why the waiver was granted.
An override matches exactly one manifest digest. For a multi-arch image, pulls are enforced against the per-platform child manifest, not the index digest, so override the child digest that &ldquo;chainctl policies check&rdquo; reports as enforced; overriding the index digest alone may not unblock the pull.
Creating an override requires the policies.override.create capability, a separate capability typically held by organization owners.
chainctl policies override create --policy POLICY --digest DIGEST --reason REASON [--parent ORG] [--output=json|table] [flags] Examples # Waive the no-eol policy for a specific image digest chainctl policies override create --policy=no-eol --parent=engineering \ --digest=sha256:&lt;64-hex-digest&gt; --reason=&#34;approved exception, ticket OPS-42&#34; Options --digest string The sha256 image digest to waive, as sha256: followed by exactly 64 lowercase hex characters (tags and other algorithms are rejected before any API call). For a multi-arch image use the per-platform child digest that &#34;chainctl policies check&#34; reports, not the index digest. --parent string The name or id of the organization to scope the override to. --policy string The name or UIDP of the policy to override. --reason string The justification for the override. --resource-type string Resource type used to disambiguate a policy referenced by name (shorthand: Repo, Python, Java, Javascript; or a full type). Ignored when the policy is given by UIDP. Options inherited from parent commands --api string The url of the Chainguard platform API. (default &#34;https://console-api.enforce.dev&#34;) --audience string The Chainguard token audience to request. (default &#34;https://console-api.enforce.dev&#34;) --config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly. --console string The url of the Chainguard platform Console. (default &#34;https://console.chainguard.dev&#34;) --force-color Force color output even when stdout is not a TTY. -h, --help Help for chainctl --issuer string The url of the Chainguard STS endpoint. (default &#34;https://issuer.enforce.dev&#34;) --log-level string Set the log level (debug, info) (default &#34;ERROR&#34;) -o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide] -v, --v int Set the log verbosity level. SEE ALSO chainctl policies override	- Manage policy overrides. 
