What you will be able to do
- Add or update a tag on a Unity Catalog object from its Overview page in Catalog Explorer
- Name the privileges needed to apply an ordinary tag and the extra permission a governed tag needs
- Tell ungoverned, governed and system tags apart by their icons and rules, and use system.certification_status to certify or deprecate an asset
- Apply tags with SQL and stay within the tag constraints, including the rule for dropping a column that has a governed tag
Key concept
Catalog Explorer as the object's control panel — Catalog Explorer is the Catalog UI in the workspace sidebar. In it you open one Unity Catalog object and see its full metadata. Both tasks in this objective start there: you add tags on the object's Overview page and you trace its data flow on its Lineage tab.
1.What a tag is and what you can tag
A tag in Unity Catalog is a key with an optional value. You attach it to a securable object to organize and categorize it. Tags also do practical work: tag keys and values are searchable from the workspace search bar, so a well-chosen tag helps other analysts find the table they need. One detail matters when you write search terms: tag search requires exact term matching.
You can tag far more than tables. Securable-object tagging covers catalogs, schemas, tables, table columns, volumes, views, functions, registered models, model versions, external metadata objects and services. Dashboards, Genie Agents, Databricks apps and notebooks can be tagged too, but each has its own page for doing so.
Tag data is stored as plain text and may be replicated globally. The documentation says not to put personal or sensitive information in tag names, values or descriptors. A tag should describe a category of data, such as pii = ssn, and never contain the data itself.
Checkpoint 1 of 7· Check yourself
Which of these tags follows the documented guidance for Unity Catalog tags?
Tags are stored as plain text and may be replicated globally, so they must not hold personal or sensitive information. A cost-center classification is exactly the kind of organizing attribute tags are meant for.
“do not use tag names, values or descriptors that contain personal or sensitive information”Source: docs.databricks.com
Sources1
2.Adding a tag in Catalog Explorer
Before you open the UI, check that you have permission. To add tags to a securable object, you must either own the object or hold all three of these privileges: APPLY TAG on the object, USE SCHEMA on its parent schema, and USE CATALOG on its parent catalog. APPLY TAG alone is not enough. You also need to be able to reach the object through its schema and catalog.
Checkpoint 2 of 7· Check yourself
An analyst has APPLY TAG on the table sales.emea.orders but no other privileges, and does not own it. What else do they need before they can tag it?
A non-owner needs APPLY TAG on the object plus USE SCHEMA on the parent schema and USE CATALOG on the parent catalog. SELECT and MODIFY are not part of the tagging requirement.
“To add tags to Unity Catalog securable objects, you must own the object or have all of the following privileges:”Source: docs.databricks.com
The UI path is short. Click Catalog in the sidebar and select the object. On its Overview page, find the Tags area. If the object has no tags yet, click the Add tags button. If it already has some, click the Add/Edit tags icon. Then choose an existing tag key and value, or type the name of a new tag. The picker groups tags into two sections. Governed tags appear under a Governed header with a lock icon, and everything else appears under Other. An Include system tags toggle shows or hides system tags.
No. A tag key is always required, but whether you need a value depends on the tag key. A governed tag may be key-only, or it may restrict you to a list of allowed values.
Checkpoint 3 of 7· Put it in order
Put the Catalog Explorer steps for tagging a table in order
- 1.Click Catalog in the sidebar
- 2.On the object's Overview page, under Tags, click Add tags (or the Add/Edit tags icon)
- 3.Select an existing tag key and value, or enter a new tag
- 4.Select the securable object
You go to Catalog, pick the object, open the Tags area of its Overview page, and only then choose the key and value.
“On the object Overview page, under Tags, add or update a tag”Source: docs.databricks.com
Sources1
3.Governed tags, system tags and the certification badge
Not every tag in the picker behaves the same way. A governed tag is an account-level tag with a tag policy. The policy defines the allowed values and controls which users and groups can assign the tag. Two things change for the person applying it. First, the value must come from the policy's list. Second, you need the ASSIGN permission on that governed tag in addition to the normal tagging privileges. Deleting a governed tag does not remove it from objects. The assignments stay in place but become ungoverned, so anyone can modify them without the extra permission.
System tags are a special type of governed tag whose keys and values are predefined by Databricks. Users cannot modify or delete them, but governed tag permissions still control who can assign them. For a data analyst, the most important one is system.certification_status. It has exactly two values: certified, meaning the asset meets internal standards for accuracy, completeness and trust, and deprecated, meaning it is outdated and should not be used in new work. The badge appears next to the object's name, and the tag affects how the data appears in notebooks and the SQL editor.
| Tag kind | UI marker | Who defines keys and values | What you need to assign it |
|---|---|---|---|
| Ungoverned tag | Listed under Other | Whoever applies it | Ownership, or APPLY TAG + USE SCHEMA + USE CATALOG |
| Governed tag | Lock icon, listed under Governed | The tag policy (allowed values) | The tagging privileges plus ASSIGN on the governed tag |
| System tag (e.g. system.certification_status) | Wrench icon, shown via Include system tags | Databricks; users cannot modify or delete it | Controlled through governed tag permission settings |
Checkpoint 4 of 7· Match them up
Match each icon you see in Catalog Explorer to what it tells you
Tap a term, then the definition that fits it.
Lock means governed and wrench means system. The certification_status values appear as a check mark for certified and a restricted icon for deprecated.
“Certified assets display a check mark in Catalog Explorer; deprecated assets display a restricted icon.”Source: docs.databricks.com
Checkpoint 5 of 7· Exam question
A data steward already has `USE CATALOG` and `USE SCHEMA` on the `sales` catalog and schema. In Catalog Explorer, they try adding the governed tag `data_classification = restricted` to the `customers` table, and the assignment fails, even though `restricted` is a listed allowed value for that tag. What most likely explains the failure?
Correct answer: C — Governed tag policies can restrict which specific allowed values a user may assign, so the steward needs that value-level permission granted separately by the tag administrator.
- A. This is incorrect because governed tags apply to tables and even individual columns, not just catalogs and schemas, so the object type is not the problem here.
- B. This is incorrect because nothing in the scenario indicates the table is near a tag limit, and hitting a count cap would not produce a permission-specific rejection tied to one value.
- C. This is correct because governed tag policies can restrict assignment down to the value level, so a user can be authorized for the catalog and schema yet still lack permission to apply one specific allowed value.
- D. This is incorrect because a session timeout would block all Catalog Explorer actions uniformly, not fail selectively on a single tag value while other privileges already work.
4.Tagging with SQL, and the limits that apply
Anything you can do in the Tags area of the UI you can also do in SQL. On Databricks Runtime 16.1 and above, the SET TAG and UNSET TAG statements manage tags on securable objects. The example below tags a catalog with a cost center.
SET TAG ON CATALOG catalog `cost_center` = `hr`;On Runtime 13.3 and above, the older form is an ALTER statement with a SET TAGS or UNSET TAGS clause. The documentation uses it to put a governed tag on a single column:
Checkpoint 6 of 7· Fill the gap
Which keyword completes this statement that tags the SSN column?
-- Add the governed tag to ssn column
ALTER TABLE abac.customers.profiles
ALTER COLUMN SSN
SET ? ('pii' = 'ssn');The ALTER form uses the plural clause SET TAGS (or UNSET TAGS). The singular SET TAG is the standalone statement available from Runtime 16.1.
Source: docs.databricks.comWhichever method you use, the same constraints apply. Tag keys are case sensitive, so Sales and sales are different tags. An object can carry at most 50 tags, and a table can have at most 1,000 column tags across all its columns. Keys and values are limited to 256 characters each, and neither may have leading or trailing spaces. Keys cannot contain the characters . , - = / : . You also cannot tag several columns in one ALTER TABLE command; each column needs its own statement. COMMENT is different here, because it does accept several columns at once. To read tags back, query the INFORMATION_SCHEMA views CATALOG_TAGS, SCHEMA_TAGS, TABLE_TAGS, COLUMN_TAGS and VOLUME_TAGS.
The documentation gives a fixed order for this, meant to prevent potential data leaks. First remove the tag with UNSET TAG ON COLUMN, then drop the column with ALTER TABLE ... DROP COLUMN. Dropping the column does not by itself erase the data, because time travel might still expose it. To delete the data permanently, follow the separate Drop columns procedure. Foreign tables are the one exception: their column tags are dropped automatically when the column is dropped in the foreign source.
Checkpoint 7 of 7· Put it in order
Put the steps for removing a column that carries a governed tag, and permanently deleting its data, in order
- 1.ALTER TABLE <catalog>.<schema>.<table> DROP COLUMN <column>
- 2.Follow the Drop columns steps to permanently delete the column's data
- 3.UNSET TAG ON COLUMN <catalog>.<schema>.<table>.<column> <tag_key>
The drop fails while a governed tag is present, so the tag has to go first. Dropping the column alone does not erase the data, so the Drop columns procedure comes last.
“To drop a tagged column, you must first remove all governed tags from it.”Source: docs.databricks.com
Sources1
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Deleting a governed tag removes that tag from every object that carried it.Why is that wrong?
The tag assignments stay on the objects but become ungoverned, so anyone can then modify them without the governed-tag permission.
Covered in Governed tags, system tags and the certification badge
2.Tag keys are case-insensitive, so 'Sales' and 'sales' are the same tag.Why is that wrong?
Tag keys are case sensitive, and those two keys are distinct tags.
Covered in Tagging with SQL, and the limits that apply
3.Like COMMENT, one ALTER TABLE statement can set tags on several columns at once.Why is that wrong?
Each column must be tagged separately. COMMENT is the clause that accepts multiple columns.
Covered in Tagging with SQL, and the limits that apply
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Using tags also simplifies the search and discovery of tables and views using the workspace search functionality.”
↩︎ What a tag is and what you can tag“Securable object tagging is currently supported on catalogs, schemas, tables, table columns, volumes, views, functions, registered models, model versions”
↩︎ What a tag is and what you can tag“Tag search requires exact term matching.”
↩︎ What a tag is and what you can tag“USE SCHEMA on the object's parent schema”
↩︎ Adding a tag in Catalog Explorer“Tag keys are required. Whether a tag value is required depends on the tag key.”
↩︎ Adding a tag in Catalog Explorer“To add a governed tag to Unity Catalog securable objects, you must also have the ASSIGN permission on the governed tag.”
↩︎ Governed tags, system tags and the certification badge“System tags are a special type of governed tag that are predefined by Databricks.”
↩︎ Governed tags, system tags and the certification badge“You can assign a maximum of 50 tags to a single securable object (table or column).”
↩︎ Tagging with SQL, and the limits that apply“You cannot assign tags to multiple columns in a single ALTER TABLE command.”
↩︎ Tagging with SQL, and the limits that apply“Otherwise, time travel might expose the data.”
↩︎ Tagging with SQL, and the limits that apply“The tags remain on objects, but anyone can assign or modify them without requiring permissions.”
↩︎ Exam trap 1“Tag keys are case sensitive. For example, Sales and sales are two distinct tags.”
↩︎ Exam trap 2“This differs from the COMMENT clause, which does support multiple columns in one command.”
↩︎ Exam trap 3“do not use tag names, values or descriptors that contain personal or sensitive information”
↩︎ Checkpoint“To add tags to Unity Catalog securable objects, you must own the object or have all of the following privileges:”
↩︎ Checkpoint“On the object Overview page, under Tags, add or update a tag”
↩︎ Checkpoint“When you drop a column that has one or more governed tags assigned, the drop operation fails.”
↩︎ Prediction“To drop a tagged column, you must first remove all governed tags from it.”
↩︎ Checkpoint - 2.https://docs.databricks.com/aws/en/data-governance/unity-catalog/certify-deprecate-dataOfficial docs
“It is a system-governed tag with two tag values: certified and deprecated.”
↩︎ Governed tags, system tags and the certification badge“The tag is displayed next to object names in the workspace, and influences how data appears in notebooks and the SQL editor.”
↩︎ Governed tags, system tags and the certification badge - 3.
“Governed tags are marked with a lock icon and grouped under Governed in the tag assignment dropdown.”
↩︎ Governed tags, system tags and the certification badge“Certified assets display a check mark in Catalog Explorer; deprecated assets display a restricted icon.”
↩︎ Checkpoint
Also cited
“including details that the curated view doesn't surface: object properties, permissions, sample data, and lineage”
↩︎ Key concept