CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 2 · Lesson 4/39

    Certify and Deprecate Data with Unity Catalog Tags

    Use Unity Catalog to discover, query, and manage certified datasets.

    10 min read
    2.56% of exam
    4 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Explain what the system.certification_status tag tells data consumers and which objects it can be applied to
    • Identify the privileges needed to certify or deprecate a Unity Catalog object
    • Apply certified or deprecated status through the workspace UI and with SET TAG in SQL
    • Distinguish governed tags from ordinary tags, and know where tag inheritance applies and where it does not

    Key concept

    Certification status tag (system.certification_status) — A system-governed tag with exactly two values. certified marks an asset that your organization vouches for, and deprecated marks one that is outdated and should not be used. The badge appears next to the asset everywhere in the workspace, so readers can judge an asset before they query it.

    1.What a certified badge tells a data consumer

    A large catalog usually holds several tables that look like they answer the same question: a carefully maintained sales table, an analyst's scratch copy, and a summary nobody has refreshed in a year. Unity Catalog lets the organization say which one to trust. Certifying an asset signals that it meets your organization's standards. Deprecating an asset warns people that it is outdated. Databricks describes this as a layer that sits on top of your metric views, domains and Pages: certification adds a layer of trust and authority on top of those definitions. Genie One also uses the signal and prioritizes the assets your organization vouches for.

    Under the hood, certification is just a tag. The key is system.certification_status, and the workspace turns its value into a visual badge. The badge appears next to object names in the workspace and also changes how the data appears in notebooks and the SQL editor. Analysts therefore see the warning where they write queries, not only when they browse the catalog.

    The two values of system.certification_status
    Tag valueMeaningIndicator in the workspace
    certifiedThe asset has met internal standards for accuracy, completeness, and trustCheck mark
    deprecatedThe asset is outdated, no longer reliable, or should not be used in new workflowsRestricted icon

    The tag isn't limited to tables. You can apply it to catalogs, schemas, tables, views, volumes, functions, registered models, dashboards, Genie Agents, Databricks Apps and notebooks. A team can therefore certify both a gold table and the dashboard built on top of it.

    Checkpoint 1 of 6· Check yourself

    An analyst sees a table in the SQL editor with a restricted icon next to its name. What does that tell them?

    Sources1

    2.Applying the certification status tag

    Two separate permission checks apply. The first is on the tag itself. Because system.certification_status is a governed tag, you need the ASSIGN permission on that governed tag. The second is on the object you are tagging: you must own it, or hold APPLY TAG on it plus USE SCHEMA on its parent schema and USE CATALOG on its parent catalog. In the steward's case, APPLY TAG and the USE privileges cover only the object. Without ASSIGN on the tag, they cannot certify it.

    Checkpoint 2 of 6· Check yourself

    Which privilege, beyond the usual object-level tagging privileges, does a user need to certify a table?

    Once the permissions are in place, you can set the status in the workspace UI or in SQL. In the UI, you work from the object's kebab menu, and the dialog offers a third choice, None, which clears the status. You can change or remove the status at any time, so deprecating a table is not a one-way decision.

    Checkpoint 3 of 6· Put it in order

    Put the workspace UI steps for certifying an object in order

    1. 1.Select Certified, Deprecated, or None
    2. 2.Click Save
    3. 3.Navigate to a supported object
    4. 4.Click the kebab menu and select Assign certification

    In SQL, certification is an ordinary SET TAG statement. The tag key and its value are both wrapped in backticks, and the table is named with its full three-level name.

    Certifying a table with SET TAGsql
    -- Apply certified tag key
    SET TAG ON TABLE main.sales.transactions `system.certification_status` = `certified`;

    Checkpoint 4 of 6· Fill the gap

    The old summary table should carry the restricted icon. Which value completes the statement?

    SET TAG ON TABLE main.sales.old_summary `system.certification_status` = ` ? `;

    Checkpoint 5 of 6· Exam question

    A data analyst at a retail company wants to search Catalog Explorer for only the tables that have been certified as trustworthy for analysis, without manually checking each table's status. Which search approach lets them filter the results to just certified assets?

    Sources1

    3.Governed tags, and certifying at scale

    Certification is one case of a more general feature. Tags are keys with optional values that you attach to securable objects to organize them, and they make tables and views easier to find through workspace search. Ordinary tags are free-form, so one team might write PII while another writes pii. Governed tags fix this. An admin marks a tag key as governed and defines its allowed values. For example, a governed sensitivity tag might accept only public, internal or restricted. After that, only users with ASSIGN on the governed tag can set its values, and changing the tag's definition requires MANAGE on it. Because tag data is stored as plain text and may be replicated globally, tag names and values should never contain personal or sensitive information.

    Editing a governed tag's description and allowed valuessql
    -- Update the description.
    ALTER GOVERNED TAG pii SET DESCRIPTION 'Indicates what kind of personal identifiable information the asset contains';
    
    -- Replace the allowed values list.
    ALTER GOVERNED TAG sensitivity_level SET VALUES ('low', 'medium', 'high');

    Two details matter here. First, SET VALUES replaces the whole list of allowed values; it does not add to it. Second, if an admin deletes a governed tag, its assignments become ungoverned, and anyone with APPLY TAG can then change them without ASSIGN.

    Who can set a tag's value, by kind of tag
    Kind of tagAllowed valuesWho can assign a value
    Ordinary (ungoverned) tagAny key and optional valueObject owner, or a user with APPLY TAG plus USE SCHEMA and USE CATALOG
    Governed tagOnly the admin-defined listUsers who also hold ASSIGN on the governed tag
    system.certification_statuscertified or deprecatedUsers who also hold ASSIGN on system.certification_status

    Setting the tag by hand works for a few tables, but not for hundreds. To certify or deprecate many objects, Databricks recommends automating tag assignment (Beta). An automation assigns system.certification_status to every table or volume that matches conditions you define, such as query usage, asset age, owner, description, name or existing tags. The documented example finds every table in a temp catalog that has had no read or write queries in 30 days, marks it deprecated, and emails the owners.

    Finally, don't confuse tagging a container with tagging its contents. When you tag a catalog, its schemas and tables inherit that tag only while attribute-based access control (ABAC) policies are evaluated, and even then the tag does not reach the column level. For every other purpose, including what a user sees on a table, each object keeps only its own tags.

    Checkpoint 6 of 6· Check yourself

    An admin certifies the main catalog. When does a table inside main implicitly carry that catalog's tag?

    Sources2341

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Anyone with APPLY TAG on a table, plus USE SCHEMA and USE CATALOG, can mark it certified.Why is that wrong?

      Those privileges are enough for ordinary tags only. Certification is a governed system tag, so the user also needs ASSIGN on system.certification_status.

      Covered in Applying the certification status tag

    2. 2.Tagging a catalog or schema automatically tags every table beneath it.Why is that wrong?

      Child objects inherit tags only while ABAC policies are evaluated, and never at the column level. Otherwise, each object carries only its own tags.

      Covered in Governed tags, and certifying at scale

    3. 3.ALTER GOVERNED TAG ... SET VALUES adds the listed values to the existing allowed values.Why is that wrong?

      SET VALUES is declarative. The list you provide replaces every existing allowed value.

      Covered in Governed tags, and certifying at scale

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “The tag is displayed next to object names in the workspace, and influences how data appears in notebooks and the SQL editor.”
      ↩︎ What a certified badge tells a data consumer
      “certification adds a layer of trust and authority on top of those definitions”
      ↩︎ What a certified badge tells a data consumer
      “To add tags to Unity Catalog securable objects, you must own the object or have all of the following privileges:”
      ↩︎ Applying the certification status tag
      “You can update or remove the status at any time.”
      ↩︎ Applying the certification status tag
      “To certify or deprecate data across many objects, Databricks recommends automating tag assignment.”
      ↩︎ Governed tags, and certifying at scale
      “It is a system-governed tag with two tag values: certified and deprecated.”
      ↩︎ Key concept
      “You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”
      ↩︎ Exam trap 1
      “It is a system-governed tag with two tag values: certified and deprecated.”
      ↩︎ Prediction
      “Deprecated assets display a restricted icon in the workspace.”
      ↩︎ Checkpoint
      “You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”
      ↩︎ Checkpoint
      “Click the kebab menu and select Assign certification.”
      ↩︎ Checkpoint
    2. 2.
      “With governed tags, admins mark specific tag keys as governed and define the set of allowed values for each.”
      ↩︎ Governed tags, and certifying at scale
    3. 3.
      “Going forward, only users with the ASSIGN privilege on the department governed tag can assign or modify department tag values.”
      ↩︎ Governed tags, and certifying at scale
      “To edit a governed tag, you must have the MANAGE permission on that governed tag.”
      ↩︎ Governed tags, and certifying at scale
      “This means that any user with the APPLY TAG privilege can assign or modify those tag values without requiring the ASSIGN privilege.”
      ↩︎ Governed tags, and certifying at scale
      “SET VALUES is declarative: the provided list replaces all existing allowed values.”
      ↩︎ Exam trap 3
    4. 4.
      “Tag data is stored as plain text and may be replicated globally.”
      ↩︎ Governed tags, and certifying at scale
      “Implicit tag inheritance occurs when evaluating ABAC policies only. Tag inheritance doesn't apply generally.”
      ↩︎ Exam trap 2
      “Implicit tag inheritance occurs when evaluating ABAC policies only.”
      ↩︎ Checkpoint

    Continue to page 2 of 2

    Find, Inspect, and Query Certified Data in Unity Catalog

    Spotted a mistake, or was something unclear? Tell us.