Skip to content

Release Notes 2026

  • Security Intelligence Scout — a new self-serve way to monitor database activity for Oracle, SQL Server, PostgreSQL, and MySQL databases. Security Intelligence Scout reads your database’s native audit trail on a schedule, so there’s no need to route traffic through a proxy. Activity it captures is available alongside your existing database activity monitoring — in Query Audit Logs, the Activity Dashboard, DAM Alerting, and Audit Reports. Set it up entirely from the Agents page — register an agent, configure your database’s audit settings, and define scan tasks.
  • Amazon Comprehend condition — compound-ruleset classifiers can now match on Amazon Comprehend’s PII entity detection, joining Google DLP and Snowflake Native as external classification signals.
  • Data Length and Column Size conditions — two new ways to match columns in compound rulesets: by the byte length of sampled values, or by a column’s declared schema size.

Snowflake Native classification retired as a standalone method

Section titled “Snowflake Native classification retired as a standalone method”

Snowflake Native is no longer available as a standalone classification method for new classification jobs — new jobs on Snowflake now choose between ALTR Native and Google DLP. The same detection is still available: add a Snowflake Native condition within an ALTR Native classifier.

  • Notification integrations management — a new Settings → Integrations page gives you one place to manage the channels that deliver your alerts: Slack, webhook, Splunk, PagerDuty, Microsoft Teams, and ServiceNow. For each channel you can view every connection and its status, send a test delivery, and add, edit, or delete connections. A connection that an alert rule is still using can’t be deleted until you remove it from those rules, and a connection whose deliveries are failing is flagged so you can correct it.
  • Acknowledge a triggered alert — the action button on a triggered alert is now labeled Acknowledge (previously “Approve”).
  • Fuller alert details for OLTP — match-rule alert details for OLTP database events now show the database, schema, table, and statement text behind the alert, matching what’s already shown for Snowflake.
  • Back button in the Add Policy wizard — the Add Policy wizard now has a Back button at each step, so you can step backward through the wizard instead of starting the policy over.
  • Reliable scheduled classification tasks — recurring (scheduled) classification tasks that use metadata-only sampling can now be created without error (this configuration was previously rejected).
  • System Audits for alerting and integrationsSystem Audits now records changes to your alerting setup. The Alerts category logs when alert rules and their comments are created, updated, or deleted, and the Integrations category logs changes to your notification-integration configurations — the channels that deliver alerts, such as email, Slack, Microsoft Teams, PagerDuty, Splunk, ServiceNow, and webhooks. This gives you a complete change-history trail for who changed your alerting and delivery configuration.
  • Alerting — create alert rules that watch database activity and notify you when it matches. Build match or threshold rules over fields like user, query type, table and column, masked-data access, denials, and volume; assign a severity; and deliver notifications to email, Slack, Microsoft Teams, PagerDuty, Splunk, ServiceNow, and other webhooks. Alerting works on both Snowflake and OLTP, and is notification-only (it does not block queries).
  • Snowflake Native conditions in compound rulesets — you can now add Snowflake’s privacy and semantic categories as conditions in the compound ruleset builder, combined with regex, Google DLP, and other condition types using AND/OR/NOT logic. Available for Snowflake.
  • Column content conditions — classifiers can match on the content format detected in a column, including JSON, XML, CSV, Base64, PDF, Microsoft Office documents (DOCX, XLSX, PPTX), RTF, images (PNG, JPEG, GIF, TIFF), archives (ZIP, GZIP), and Parquet. Select one or more formats and set a minimum match threshold.
  • Automatic tagging for ALTR Native jobs — automatic tagging now applies tags from ALTR Native classification results, in addition to Google DLP and Snowflake Native. Classifier name matching is now case-insensitive.
  • Compound rulesets on Databricks — Google DLP classification jobs on Databricks now evaluate compound rulesets with decision lineage.
  • PostgreSQL SCRAM authentication — the OLTP sidecar now supports SASL/SCRAM-SHA-256, allowing ALTR to proxy PostgreSQL databases that require SCRAM authentication.
  • Audit records now include additional detail across database engines, including the original client hostname for SQL Server and application name and connection identifiers for MySQL.
  • Processing location — ALTR-native Snowflake classification jobs now have a processing location setting. Choose ALTR Hosted (default) to run classification in ALTR’s infrastructure, or In-Warehouse to execute classification directly inside your Snowflake warehouse via SQL UDF pushdown. OLTP jobs always run on the classification agent.
  • Ignored rules in match breakdown — the match breakdown tooltip (hover a confidence badge in the classification report) now shows rules that were evaluated but did not affect the final confidence score, labeled “ignored.” Helps diagnose why a configured rule did not fire.
  • Audit Report event category — scheduled audit report activity is now visible in System Audits under the Audit Report category.
  • The execution status filter is now a single-select dropdown for simpler success/failure filtering.
  • Rule lists now render significantly faster for policies with large numbers of rules.
  • The timezone selector hides deprecated timezone aliases and ranks zones by relevance.
  • Fixed a bug where searching in role and user group dropdowns would stop returning results after selecting an existing option.
  • Passkeys are now available as a second authentication factor. Register a passkey (such as Touch ID or a hardware security key) from Settings > Preferences. Passkeys are an additional option alongside existing 2FA methods (SMS, Email, Authenticator App).
  • Match confidence explanations — each High / Medium / Low confidence badge in the classification report now shows a one-sentence explanation on hover describing why that score was assigned. Confidence scores are available on reports run after April 13, 2026.
  • The schedule details panel now shows whether the last scheduled run succeeded or failed, in addition to when it ran.
  • Fixed a bug where clicking Discard Changes while editing a Unified Policy would return to the same page instead of the link you originally clicked.
  • Classification Report now shows Match Confidence scores (High / Medium / Low) for each matched row. Hover a score to see a one-sentence explanation of the result. Click in to view the specific rule results that contributed to the match. Match Confidence is available for jobs run after April 13, 2026.

Build classifiers using multiple conditions with AND/OR/NOT logic. The Classifier Editor now supports nested condition groups. Combine ALTR Regex, Snowflake Native, and Data Location rule types using AND, OR, and NOT operators to precisely target the data you want to classify. Conditions can be nested to any depth.

  • Classification Report results are now directly linkable. The report detail view has its own URL — bookmark it or share a link with teammates to open a specific report result directly.
  • Scheduled Audit Reports — fixed cron schedule expression validation and an issue where archived report definitions would stop generating report instances.

Audit Reports is a brand-new capability for turning ALTR’s database activity monitoring data into formatted, reviewable compliance artifacts. Generate reports of database activity — who performed actions, what they did, and when — and review and attest to them inside ALTR.

  • Run reports on demand or on a recurring schedule.
  • Each generated report produces both a PDF (formatted, capped at 10,000 rows) and a CSV (uncapped — the source of truth for high-volume reports).
  • Optional review-and-attestation workflow: configure zero or more approvers per report definition. Reviewers can comment and approve, and approvals are captured as a durable audit trail.
  • Available for OLTP data sources (Oracle, SQL Server, PostgreSQL, MySQL) via the ALTR sidecar.
  • The Classification Report grid now includes a page size picker so you can control how many rows appear per page.
  • New ORCL_SIDECAR_MODE environment variable adds a diagnostic passthrough mode for the Oracle sidecar, which forwards traffic directly to the database without inspection. Use this for troubleshooting client connection issues. Note: IDP authentication and policy enforcement are not available while passthrough mode is active — it is not intended for production use.
  • The Unified Policy API now validates OLTP policy inputs more strictly: schema identifiers are rejected for MySQL (which does not use schemas), and the database type cannot be changed after a policy is created.
  • Fixed a case where Databricks classification connections could get stuck in an “in progress” state.

ALTR’s OLTP Classification Agent and Sidecar now support two additional credential providers: Environment Variable and Secret File. These join the existing AWS Secrets Manager and Azure Key Vault options, enabling OLTP deployments in environments where cloud-native secret managers aren’t available. The Secret File provider supports live credential rotation without container restarts.

Large classification reports now load significantly faster.

The OLTP Classification Agent now supports SSL/TLS configuration for database connections.

ALTR’s outbound email provider has changed. Emails from ALTR — including classification reports, security notifications, and account alerts — now send from noreply@flare.altr.com. If you aren’t receiving ALTR emails, check your spam folder and allowlist the new sender domain. Learn more

ALTR-native classification on Snowflake now performs better on large schemas and scales with warehouse size. No configuration changes required — customers benefit automatically. Learn more

ALTR-native classification on OLTP databases (Oracle, MySQL, PostgreSQL, SQL Server) now performs better on large schemas. Customers benefit automatically on their next classification run. Learn more

When running a classification job, sample size and type are now configured in a dedicated Sample Size step that applies uniformly to all classifiers in the job. Previously, sampling was configured per-classifier. Learn more

GDLP classification is now available for OLTP databases. Use your own Google credentials (BYOK) to run scans on data in your OLTP data sources. Learn more

To get started with data classification for OLTP data sources, contact support@altr.com.

You can now create ALTR Native Classification rules that match columns by name, not just by scanning column contents. This is useful when the column name itself is a reliable indicator of sensitive data — for example, columns named ssn, email, or card_number. Learn more

The System Audit log now shows the username of who performed each action. Previously, audit entries recorded the action but not the actor — every entry now includes the user responsible for the change. Learn more

Fixed an issue where saving policies with a large number of rules (1,000+) could time out before completing. Large policy updates now apply reliably.

We are busy enhancing ALTR, but nothing is ready to be released just yet. Check back next week!

We are busy enhancing ALTR, but nothing is ready to be released just yet. Check back next week!

The OLTP Repository Activity Monitoring Dashboard now supports a 24-hour view. Switch between the last 24 hours and the last 7 days, and all metrics will update accordingly.

You can now monitor repository activity in ALTR with the new OLTP Repository Activity Monitoring Dashboard, available for customers using OLTP sidecar integrations.

The Activity Monitoring Dashboard gives you a real-time view of how, when and by whom data is accessed to help you validate policy effectiveness, detect unusual activity, and support audits or compliance reviews. Learn more.

We now support MySQL 8.0 databases. You can securely manage access to MySQL 8.0 databases at scale using ALTR’s sidecar proxy-based connection. To get started using MySQL 8.0, contact ALTR Support .

We updated the impersonation policy creation flow to include a step for selecting a repository type. This ensures the Data Source dropdown shows only data sources associated with the selected repository type, instead of all OLTP data sources, and aligns this flow with other policy creation experiences.

We now support PostgreSQL databases. You can securely manage access to PostgreSQL databases at scale using ALTR’s sidecar proxy-based connection. To get started using PostgreSQL, contact ALTR Support .

The Data Usage Analytics heat map (under the Analytics menu) and it’s associated Import Data Usage History toggle (on the Data Sources page) have been removed. These capabilities are now replaced by the Activity Monitoring Dashboard, which provides a more flexible and comprehensive way to monitor data usage and activity. All data remains available through query audits.

  • Snowflake and Google DLP classification scans are now run from the Data ClassificationClassification Reports menu instead of the Data Sources page. This change centralizes all classification scans and reports. As part of this update, previous classification reports are no longer available. To view classification results, run a new scan to regenerate the report. Learn more.
  • Editing policy rules is now more reliable. Updates are processed more efficiently, reducing the chance of failures in larger policies.

The option to sync Snowflake object tags in the ALTR user interface has been deprecated. You can still perform tag syncing through ALTR’s API.

This change affects the former “Snowflake Classification and Object Tags” and “Snowflake Object Tags” classification options. Classification now relies on Snowflake’s built-in features and no longer syncs object tags into ALTR.