Opens in a new tab
vmblog logo 2024 wht (updated)

Liquibase Secure 6.0 Moves Database Change Governance From Pipelines to the Enterprise

Share: 

David Marshall | Published: October 1, 2026

Anyone who has run database changes through a modern delivery pipeline knows the pattern. Application code gets plenty of automated scrutiny, but the database layer often depends on policies scattered across pipeline configs, repositories, and individual team habits. That was manageable when releases were slower and the people writing SQL were a small, known group. It is much harder now that AI-assisted development is multiplying the volume of change and the number of hands behind it.

That tension is the backdrop for the general availability of Liquibase Secure 6.0, announced September 30, 2026. Liquibase, which positions itself as the leader in Database Change Governance, is framing the release as a shift in where governance lives: away from pipeline-by-pipeline setup and toward a single enterprise-level layer.

The company boils the release down to three questions that get harder to answer as change volume rises: What changed? Was it allowed? Who controls the rules?

Change Intelligence: Visibility That Leads to Action

The headline addition is Change Intelligence, a new capability that pulls deployment activity, environment status, drift, policy outcomes, failures, and change history into one view across applications, pipelines, teams, and environments.

Anyone who has had to reconstruct an incident from pipeline logs, tickets, and screenshots will see the appeal. Liquibase says teams can now see how changes move between environments, where risk is accumulating, and what needs attention, without stitching the story together by hand.

The release also leans into remediation. When a deployment fails, AI-driven analysis explains what happened and offers guidance on resolving it, with the goal of shortening time to fix. Change Intelligence also centralizes audit evidence, giving engineering, security, and compliance teams a structured record of database change across the delivery lifecycle. That is a practical benefit for organizations that currently chase down audit artifacts at review time.

Policy Management Gets a GUI

The second pillar is a new graphical interface for policy management. Until now, governing database change at scale often meant command-line expertise and configuration repeated across pipelines. The new interface lets teams create, organize, apply, and manage policies from one place.

Liquibase ships it with more than 50 prebuilt policy rules drawn from its experience with large, complex enterprises. Teams can start from those controls, group them into reusable policy packages, and apply them to the applications and environments where they matter.

Exceptions are treated as a first-class part of the model rather than a workaround. When an exception is legitimate, teams can scope where it applies, document the reasoning, control who is allowed to grant it, and keep the decision in the audit history. It is a realistic acknowledgment that not every application, data product, or database operates the same way, and that rigid, one-size-fits-all rules tend to get bypassed.

Role-Based Access Control for the Rulebook

Centralizing policy raises an obvious follow-up: who gets to edit it? Liquibase Secure 6.0 adds role-based access control covering who can manage policies, assignments, exceptions, and governed assets.

The practical outcome is separation of duties. Database, platform, security, and compliance teams can own the standards, while developers keep moving within those boundaries. Governance ownership is distinct from delivery ownership, which is the kind of clean division auditors like to see without forcing developers into a ticket queue.

Governance Aimed at the AI Era

Liquibase is explicit about the AI angle. Faster AI-assisted development erodes its own advantage if every extra change demands manual review. The company’s argument is that when standards are defined up front and enforced automatically, organizations can move faster without a human reviewing every database change, and that the same policies apply whether a change was written by a developer or generated with AI assistance.

“AI is dramatically increasing the volume of application and database change enterprises produce. Governance has to become a force multiplier for that innovation, not the thing that slows it down,” said Pete Pickerill, Co-Founder at Liquibase. He added that organizations can establish the rules once, automate enforcement, and give teams more freedom because the right controls are already in place.

Breadth matters here too. Liquibase Secure supports more than 65 database platforms, which gives organizations a consistent governance layer across mixed database estates. For platform and DevOps teams, that means database self-service can scale without a matching rise in governance overhead. Database teams spend less time rebuilding controls and reviewing routine changes, and security and compliance teams can place controls and evidence closer to the point of change.

Availability

Liquibase Secure 6.0 is generally available as of September 30, 2026. The release includes Change Intelligence, the graphical policy management interface, role-based access control, governed exception management, and the prebuilt policy rules. More information is available at www.liquibase.com/liquibase-secure.

The Bottom Line

Database change has long been the awkward neighbor in DevOps: critical, risky, and often governed with the least consistency. As AI pushes more change toward production, pushing policy, visibility, and access control into one enterprise layer is a sensible direction. The real test will be how well the centralized model fits into existing pipelines and how much friction the prebuilt rules remove in practice, but the problem Liquibase is targeting is certainly a real one.