What changed
Formbricks 6.0, released in September and presented in its October 5 product announcement, replaces its legacy authorization evaluator with AuthZed SpiceDB as the sole runtime decision engine. PostgreSQL still holds roles and grants, but authorization decisions require a prepared SpiceDB relationship graph; there is no fallback. Operators moving self-hosted v5 installations must stop writers, take coordinated backups, prepare the graph with the target image, pass independent audits and explicitly acknowledge the migration before starting v6. Separately, Embedded Data V1 lets survey responses carry plan, device and experiment context for segmented analysis. Formbricks says legacy Survey Follow-ups stop working December 1, 2026, and should be moved to Workflows.
Why it matters
This is a change to production availability and upgrade risk, not just a new release of an open-source feedback tool. A self-hosted survey service collecting live responses cannot safely treat v6 as a routine image update: authorization now depends on another stateful component and an ordered migration, and failed checks should leave maintenance in place. SaaS teams using Formbricks to collect product feedback can use Embedded Data to connect responses to customer cohorts, but must also migrate any follow-up email automations before the announced cutoff.
Authorization becomes an external runtime dependency
Formbricks documents SpiceDB as the only authorization decision engine in v6. PostgreSQL remains the source of role/grant truth, with relationships prepared into SpiceDB. Missing or incorrectly configured SpiceDB can block startup or protected operations rather than silently reverting to the previous evaluator. The release also tightens consistency requirements and changes some deployment configuration.
Self-hosted upgrades need a rehearsed maintenance window
The official upgrade guide requires stopping every writer, including workers, imports and external integrations, and suspending controllers that might restart them. Operators then take a recoverable coordinated backup, run the target image's formbricks-authzed-prepare command and wait for migration, reconciliation and two independent clean authorization audits. The guide explicitly warns that a Helm rollback alone may not restore a changed database/graph state. It also says to use a tested source/target release pair; the 6.0.0 release note does not identify a tested pair, so operators should confirm their exact supported combination before upgrading.
Embedded Data makes survey feedback segmentable
The new setEmbeddedData() SDK path can attach account, plan, experiment and other context to individual responses. Formbricks lists 28 built-in fields and supports chart splits by device, country, page and other attributes. This is useful for comparing NPS, CSAT or drop-off across cohorts rather than treating survey totals as one undifferentiated metric.
Existing follow-up emails have a fixed cutoff
Formbricks' October 5 announcement says legacy Survey Follow-ups continue until December 1, 2026, then stop working. Workflows is the replacement for conditional email actions. Teams should inventory existing follow-up rules, rebuild and test equivalent workflow conditions and delivery before the cutoff.
Patch-level security matters while planning migration
After 6.0.0, Formbricks released 6.0.1 and 6.0.2 with authorization/security and dependency hardening. A published CVE record describes a stored-XSS permissions flaw fixed in 6.0.1 and 5.4.4. Teams should compare the latest supported patch with their environment, rather than using the original 6.0.0 image as an upgrade target.