T-SQL scripts are analysed with Microsoft's own grammar parser, not with text searching. Rule findings arrive with line and column numbers.
Parsing uses the official T-SQL parser library published by Microsoft. In practice this means a word inside a comment does not trigger a rule, and a target buried in a nested query is not missed.
Specific tables, views or procedures are marked as critical. A script that reads them, changes their schema or drops them triggers its own rule, and that rule is marked as never skippable.
UPDATE and DELETE without a WHERE clause, TRUNCATE, dynamic SQL, running operating system commands, linked server usage and permission changes are each caught by their own rule. Some of them block the save outright.
Naming prefixes, mandatory audit columns, SELECT star usage, INSERT without a column list and missing schema prefixes are also part of the rule set, and you switch them on or off.
SQL Change Guard keeps its own records on SQL Server. The schema is installed from numbered scripts shipped with the product, and each applied script is locked with a checksum; if an applied script is later modified, the application stops at startup.
There is a validation mode for banks and similar institutions: the application does not modify the schema, the database administrator applies the scripts through their own process, and the application account needs only read, write and execute permissions.
SQL Server 2016 and above are supported. Integrated authentication is preferred for the connection; where a password is used, it is stored encrypted.