# Project policy documents CLI commands

> This page describes the CLI commands used to manage policy documents that define permissions for project roles.

Source: https://docs.uniform.app/docs/guides/cli/commands/policy-documents

The commands in this section allow you to manage project policy documents that define permissions for project roles.

> **Prerequisites:**
>
> - Minimum CLI version: `20.49.0`
> - Managing policy documents requires a [team admin service account](https://docs.uniform.app/docs/guides/api-access/service-accounts#team-admin-service-accounts).

## Project policy document commands

### List policy documents

```bash
uniform policy-documents list -p <projectId>
```

_command_  
List policy documents for a project.

| Command | Output details |
| --- | --- |
| -p, --project  <br>_string_ | Uniform project id. If not specified, the environment variable `UNIFORM_CLI_PROJECT_ID` is used. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Format for the output (YAML or JSON) |
| -o, --filename  <br>_string (optional)_ | File name for the output. If not specified the output is written to stdout. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Uniform API key. If not specified, the environment variable `UNIFORM_API_KEY` is used. |
| --apiHost  <br>_string (optional, default value: https://uniform.app)_ | Uniform host. If not specified, the environment variable `UNIFORM_CLI_BASE_URL` is used. If the environment variable isn't set, the default value is used. |
| --verbose | Include verbose logging (default: false) |

### Pull policy documents

```bash
uniform policy-documents pull <directory> -p <projectId>
```

_command_  
Pull all policy documents from Uniform to local files. Each policy document is saved as a separate file named by role ID.

- If a directory path is specified, a separate file is created for each policy document.

| Command | Output details |
| --- | --- |
| -w, --what-if  <br>_boolean (optional)_ | If true, reports what would be done but changes no files. |
| -m, --mode  <br>string (optional, default value: mirror) | Specifies what kind of changes can be made.  <br>`create` - Create new files but don't update existing files.  <br>`createOrUpdate` - Create new files and update existing files but delete no files.  <br>`mirror` - Create new files, update existing files, and delete files that don't match existing objects in the Uniform project. |
| -d, --diff  <br>string (optional, default value: off) | Specifies which changes are written to stdout. If not specified, the environment variable UNIFORM_CLI_DIFF_MODE is used. If the environment variable isn't set, the default value is used.  <br>`off` - No changes are written.  <br>`update` - Only update changes are written.  <br>`on` - Update, create, and delete changes are written. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Format for the output (YAML or JSON) |
| -p, --project  <br>_string_ | Uniform project id. If not specified, the environment variable `UNIFORM_CLI_PROJECT_ID` is used. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Uniform API key. If not specified, the environment variable `UNIFORM_API_KEY` is used. |
| --apiHost  <br>_string (optional, default value: https://uniform.app)_ | Uniform host. If not specified, the environment variable `UNIFORM_CLI_BASE_URL` is used. If the environment variable isn't set, the default value is used. |
| --verbose | Include verbose logging (default: false) |

### Push policy documents

```bash
uniform policy-documents push <directory> -p <projectId>
```

_command_  
Push policy documents from local files to Uniform. Directory should contain one file per role ID.

- If a directory path is specified, the policy documents defined in the files in the directory are used.

| Command | Output details |
| --- | --- |
| -w, --what-if  <br>_boolean (optional)_ | If true, reports what would be done but changes no files. |
| -m, --mode  <br>string (optional, default value: mirror) | Specifies what kind of changes can be made.  <br>`create` - Create new files but don't update existing files.  <br>`createOrUpdate` - Create new files and update existing files but delete no files.  <br>`mirror` - Create new files, update existing files, and delete files that don't match existing objects in the Uniform project. |
| -d, --diff  <br>string (optional, default value: off) | Specifies which changes are written to stdout. If not specified, the environment variable UNIFORM_CLI_DIFF_MODE is used. If the environment variable isn't set, the default value is used.  <br>`off` - No changes are written.  <br>`update` - Only update changes are written.  <br>`on` - Update, create, and delete changes are written. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Format for the output (YAML or JSON) |
| -p, --project  <br>_string_ | Uniform project id. If not specified, the environment variable `UNIFORM_CLI_PROJECT_ID` is used. |
| -f, --format  <br>_string (optional, default value: YAML)_ | Uniform API key. If not specified, the environment variable `UNIFORM_API_KEY` is used. |
| --apiHost  <br>_string (optional, default value: https://uniform.app)_ | Uniform host. If not specified, the environment variable `UNIFORM_CLI_BASE_URL` is used. If the environment variable isn't set, the default value is used. |
| --verbose | Include verbose logging (default: false) |

## Example workflow

Here's a typical workflow for managing policy documents:

### 1. List policy documents

```bash
uniform policy-documents list -p <projectId>
```

### 2. Pull policy documents to local directory

```bash
uniform policy-documents pull ./policies -p <projectId>
```

### 3. Modify local files as needed

Edit the policy document files in the `./policies` directory as needed.

### 4. Preview changes with what-if mode

```bash
uniform policy-documents push ./policies -p <projectId> --what-if --diff on
```

### 5. Apply changes

```bash
uniform policy-documents push ./policies -p <projectId>
```

### 6. Cross-project sync

You can sync policy documents between projects in the same team:

```bash
# Pull from source project
uniform policy-documents pull ./policies -p <sourceProjectId>

# Push to target project
uniform policy-documents push ./policies -p <targetProjectId>
```
