The classifier reads the migration plan before any SQL executes and grades every operation. The rule is simple: dbwarden does not silently drop data. INFO operations are expected-safe schema additions; WARNING operations need review and will not pass check without acknowledgement; ERROR operations are destructive or ambiguous and fail the check outright.
dbwarden check inspects the pending plan and reports the classification. --force is an acknowledgement, not a bypass: it records that a human reviewed the classified plan and accepted the risk, which is why it should not be a default in CI. The classification is written to the .plan.json next to the generated migration, so the intent sits in the file a reviewer opens, not in a plan only the generator reads.
INFO expected safe: create table, add nullable column
WARNING needs review: SET NOT NULL, type change
ERROR blocked: DROP TABLE, DROP COLUMN, lossy engine changeWhat makes an operation ERROR?
Anything destructive or ambiguous: dropping a table or column, renaming without explicit intent, or a lossy engine change. It fails the safety check until an operator acknowledges it explicitly.
What does the force flag do?
It records that a human reviewed the classified plan and accepted the risk. It is an acknowledgement, not a bypass, and should not be a default in CI.