• Concept
  • Version · 6.0
  • Govern

Run policy checks

Last updated: September 29, 2026

Policy checks run from the command line with the checks run command, in your CI/CD pipeline or locally while you test a change. Two decisions shape what a run does. A policy assignment on your Liquibase Secure server decides which checks run, and each check's scope decides what those checks look at.

What checks run against

Liquibase sorts checks into two scopes.

  • Changelog checks run against the changesets in your changelog. They need no database connection.

  • Database checks run against the objects in a database, so they need something to inspect. That is either a live connection or a snapshot.

By default, checks run includes only changelog checks. To include database checks, set the checks-scope parameter.

Note: This is the most common surprise with checks run. A team enables a database-scoped check, runs checks, sees them pass, and concludes the check works. It never ran.

In this section

Which guide you want depends on whether your checks need a database, and on whether you want Liquibase to take the snapshot for you.

Note: The assignment and the scope are separate choices. The assignment decides which checks run, and the scope decides whether those checks look at your changelog, your database, or both.