What you will be able to do
- Explain what the system.certification_status tag tells data consumers and which objects it can be applied to
- Identify the privileges needed to certify or deprecate a Unity Catalog object
- Apply certified or deprecated status through the workspace UI and with SET TAG in SQL
- Distinguish governed tags from ordinary tags, and know where tag inheritance applies and where it does not
Key concept
Certification status tag (system.certification_status) — A system-governed tag with exactly two values. certified marks an asset that your organization vouches for, and deprecated marks one that is outdated and should not be used. The badge appears next to the asset everywhere in the workspace, so readers can judge an asset before they query it.
1.What a certified badge tells a data consumer
A large catalog usually holds several tables that look like they answer the same question: a carefully maintained sales table, an analyst's scratch copy, and a summary nobody has refreshed in a year. Unity Catalog lets the organization say which one to trust. Certifying an asset signals that it meets your organization's standards. Deprecating an asset warns people that it is outdated. Databricks describes this as a layer that sits on top of your metric views, domains and Pages: certification adds a layer of trust and authority on top of those definitions. Genie One also uses the signal and prioritizes the assets your organization vouches for.
Under the hood, certification is just a tag. The key is system.certification_status, and the workspace turns its value into a visual badge. The badge appears next to object names in the workspace and also changes how the data appears in notebooks and the SQL editor. Analysts therefore see the warning where they write queries, not only when they browse the catalog.
| Tag value | Meaning | Indicator in the workspace |
|---|---|---|
| certified | The asset has met internal standards for accuracy, completeness, and trust | Check mark |
| deprecated | The asset is outdated, no longer reliable, or should not be used in new workflows | Restricted icon |
The tag isn't limited to tables. You can apply it to catalogs, schemas, tables, views, volumes, functions, registered models, dashboards, Genie Agents, Databricks Apps and notebooks. A team can therefore certify both a gold table and the dashboard built on top of it.
Checkpoint 1 of 6· Check yourself
An analyst sees a table in the SQL editor with a restricted icon next to its name. What does that tell them?
The restricted icon is how the workspace displays the deprecated value of the certification status tag. A certified asset shows a check mark instead.
“Deprecated assets display a restricted icon in the workspace.”Source: docs.databricks.com
Sources1
2.Applying the certification status tag
Two separate permission checks apply. The first is on the tag itself. Because system.certification_status is a governed tag, you need the ASSIGN permission on that governed tag. The second is on the object you are tagging: you must own it, or hold APPLY TAG on it plus USE SCHEMA on its parent schema and USE CATALOG on its parent catalog. In the steward's case, APPLY TAG and the USE privileges cover only the object. Without ASSIGN on the tag, they cannot certify it.
Checkpoint 2 of 6· Check yourself
Which privilege, beyond the usual object-level tagging privileges, does a user need to certify a table?
Certification is a governed tag, so assigning it requires ASSIGN on that tag. On the object itself, you also need ownership, or APPLY TAG with USE SCHEMA and USE CATALOG.
“You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”Source: docs.databricks.com
Once the permissions are in place, you can set the status in the workspace UI or in SQL. In the UI, you work from the object's kebab menu, and the dialog offers a third choice, None, which clears the status. You can change or remove the status at any time, so deprecating a table is not a one-way decision.
Checkpoint 3 of 6· Put it in order
Put the workspace UI steps for certifying an object in order
- 1.Select Certified, Deprecated, or None
- 2.Click Save
- 3.Navigate to a supported object
- 4.Click the kebab menu and select Assign certification
You start on the object, open its kebab menu to reach Assign certification, pick the status, and then save.
“Click the kebab menu and select Assign certification.”Source: docs.databricks.com
In SQL, certification is an ordinary SET TAG statement. The tag key and its value are both wrapped in backticks, and the table is named with its full three-level name.
-- Apply certified tag key
SET TAG ON TABLE main.sales.transactions `system.certification_status` = `certified`;Checkpoint 4 of 6· Fill the gap
The old summary table should carry the restricted icon. Which value completes the statement?
SET TAG ON TABLE main.sales.old_summary `system.certification_status` = ` ? `;The tag accepts only certified or deprecated. The restricted icon is how the workspace displays the deprecated value; restricted is not a tag value.
Source: docs.databricks.comCheckpoint 5 of 6· Exam question
A data analyst at a retail company wants to search Catalog Explorer for only the tables that have been certified as trustworthy for analysis, without manually checking each table's status. Which search approach lets them filter the results to just certified assets?
Correct answer: A — Enter `certificationStatus:certified` in the Catalog Explorer search box, which filters results to assets tagged with the certified system tag.
- A. The `certificationStatus:certified` search keyword filters Catalog Explorer results to assets carrying the system certification tag with a certified value. This is the built-in mechanism for discovering only trustworthy, vetted datasets without opening each asset individually.
- B. There is no `tag:certified` search syntax in Catalog Explorer, and certification is not implemented as an arbitrary user-defined tag value. Using this keyword would not reliably match certified assets.
- C. Creation date has no relationship to certification status, since tables can be certified at any point after creation, including years later. Sorting by creation date would not surface certified assets reliably.
- D. Certification status is not stored as a permissions grant, so there is no `CERTIFIED` entry to find on a Permissions tab. Access control and certification are separate, independently managed concepts in Unity Catalog.
Sources1
3.Governed tags, and certifying at scale
Certification is one case of a more general feature. Tags are keys with optional values that you attach to securable objects to organize them, and they make tables and views easier to find through workspace search. Ordinary tags are free-form, so one team might write PII while another writes pii. Governed tags fix this. An admin marks a tag key as governed and defines its allowed values. For example, a governed sensitivity tag might accept only public, internal or restricted. After that, only users with ASSIGN on the governed tag can set its values, and changing the tag's definition requires MANAGE on it. Because tag data is stored as plain text and may be replicated globally, tag names and values should never contain personal or sensitive information.
-- Update the description.
ALTER GOVERNED TAG pii SET DESCRIPTION 'Indicates what kind of personal identifiable information the asset contains';
-- Replace the allowed values list.
ALTER GOVERNED TAG sensitivity_level SET VALUES ('low', 'medium', 'high');Two details matter here. First, SET VALUES replaces the whole list of allowed values; it does not add to it. Second, if an admin deletes a governed tag, its assignments become ungoverned, and anyone with APPLY TAG can then change them without ASSIGN.
| Kind of tag | Allowed values | Who can assign a value |
|---|---|---|
| Ordinary (ungoverned) tag | Any key and optional value | Object owner, or a user with APPLY TAG plus USE SCHEMA and USE CATALOG |
| Governed tag | Only the admin-defined list | Users who also hold ASSIGN on the governed tag |
| system.certification_status | certified or deprecated | Users who also hold ASSIGN on system.certification_status |
Setting the tag by hand works for a few tables, but not for hundreds. To certify or deprecate many objects, Databricks recommends automating tag assignment (Beta). An automation assigns system.certification_status to every table or volume that matches conditions you define, such as query usage, asset age, owner, description, name or existing tags. The documented example finds every table in a temp catalog that has had no read or write queries in 30 days, marks it deprecated, and emails the owners.
Finally, don't confuse tagging a container with tagging its contents. When you tag a catalog, its schemas and tables inherit that tag only while attribute-based access control (ABAC) policies are evaluated, and even then the tag does not reach the column level. For every other purpose, including what a user sees on a table, each object keeps only its own tags.
Checkpoint 6 of 6· Check yourself
An admin certifies the main catalog. When does a table inside main implicitly carry that catalog's tag?
Implicit tag inheritance happens only during ABAC policy evaluation. In general, tags do not inherit, so the table does not automatically count as certified.
“Implicit tag inheritance occurs when evaluating ABAC policies only.”Source: docs.databricks.com
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Anyone with APPLY TAG on a table, plus USE SCHEMA and USE CATALOG, can mark it certified.Why is that wrong?
Those privileges are enough for ordinary tags only. Certification is a governed system tag, so the user also needs ASSIGN on system.certification_status.
Covered in Applying the certification status tag
2.Tagging a catalog or schema automatically tags every table beneath it.Why is that wrong?
Child objects inherit tags only while ABAC policies are evaluated, and never at the column level. Otherwise, each object carries only its own tags.
Covered in Governed tags, and certifying at scale
3.ALTER GOVERNED TAG ... SET VALUES adds the listed values to the existing allowed values.Why is that wrong?
SET VALUES is declarative. The list you provide replaces every existing allowed value.
Covered in Governed tags, and certifying at scale
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://docs.databricks.com/aws/en/data-governance/unity-catalog/certify-deprecate-dataOfficial docs
“The tag is displayed next to object names in the workspace, and influences how data appears in notebooks and the SQL editor.”
↩︎ What a certified badge tells a data consumer“certification adds a layer of trust and authority on top of those definitions”
↩︎ What a certified badge tells a data consumer“To add tags to Unity Catalog securable objects, you must own the object or have all of the following privileges:”
↩︎ Applying the certification status tag“You can update or remove the status at any time.”
↩︎ Applying the certification status tag“To certify or deprecate data across many objects, Databricks recommends automating tag assignment.”
↩︎ Governed tags, and certifying at scale“It is a system-governed tag with two tag values: certified and deprecated.”
↩︎ Key concept“You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”
↩︎ Exam trap 1“It is a system-governed tag with two tag values: certified and deprecated.”
↩︎ Prediction“Deprecated assets display a restricted icon in the workspace.”
↩︎ Checkpoint“You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”
↩︎ Checkpoint“Click the kebab menu and select Assign certification.”
↩︎ Checkpoint - 2.
“With governed tags, admins mark specific tag keys as governed and define the set of allowed values for each.”
↩︎ Governed tags, and certifying at scale - 3.
“Going forward, only users with the ASSIGN privilege on the department governed tag can assign or modify department tag values.”
↩︎ Governed tags, and certifying at scale“To edit a governed tag, you must have the MANAGE permission on that governed tag.”
↩︎ Governed tags, and certifying at scale“This means that any user with the APPLY TAG privilege can assign or modify those tag values without requiring the ASSIGN privilege.”
↩︎ Governed tags, and certifying at scale“SET VALUES is declarative: the provided list replaces all existing allowed values.”
↩︎ Exam trap 3 - 4.
“Tag data is stored as plain text and may be replicated globally.”
↩︎ Governed tags, and certifying at scale“Implicit tag inheritance occurs when evaluating ABAC policies only. Tag inheritance doesn't apply generally.”
↩︎ Exam trap 2“Implicit tag inheritance occurs when evaluating ABAC policies only.”
↩︎ Checkpoint