CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 2 · Lesson 5/39

    Tag Data Assets in Catalog Explorer

    Use the Catalog Explorer to tag a data asset and view its lineage.

    11 min read
    2.56% of exam
    4 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Add or update a tag on a Unity Catalog object from its Overview page in Catalog Explorer
    • Name the privileges needed to apply an ordinary tag and the extra permission a governed tag needs
    • Tell ungoverned, governed and system tags apart by their icons and rules, and use system.certification_status to certify or deprecate an asset
    • Apply tags with SQL and stay within the tag constraints, including the rule for dropping a column that has a governed tag

    Key concept

    Catalog Explorer as the object's control panel — Catalog Explorer is the Catalog UI in the workspace sidebar. In it you open one Unity Catalog object and see its full metadata. Both tasks in this objective start there: you add tags on the object's Overview page and you trace its data flow on its Lineage tab.

    1.What a tag is and what you can tag

    A tag in Unity Catalog is a key with an optional value. You attach it to a securable object to organize and categorize it. Tags also do practical work: tag keys and values are searchable from the workspace search bar, so a well-chosen tag helps other analysts find the table they need. One detail matters when you write search terms: tag search requires exact term matching.

    You can tag far more than tables. Securable-object tagging covers catalogs, schemas, tables, table columns, volumes, views, functions, registered models, model versions, external metadata objects and services. Dashboards, Genie Agents, Databricks apps and notebooks can be tagged too, but each has its own page for doing so.

    Checkpoint 1 of 7· Check yourself

    Which of these tags follows the documented guidance for Unity Catalog tags?

    Sources1

    2.Adding a tag in Catalog Explorer

    Before you open the UI, check that you have permission. To add tags to a securable object, you must either own the object or hold all three of these privileges: APPLY TAG on the object, USE SCHEMA on its parent schema, and USE CATALOG on its parent catalog. APPLY TAG alone is not enough. You also need to be able to reach the object through its schema and catalog.

    Checkpoint 2 of 7· Check yourself

    An analyst has APPLY TAG on the table sales.emea.orders but no other privileges, and does not own it. What else do they need before they can tag it?

    The UI path is short. Click Catalog in the sidebar and select the object. On its Overview page, find the Tags area. If the object has no tags yet, click the Add tags button. If it already has some, click the Add/Edit tags icon. Then choose an existing tag key and value, or type the name of a new tag. The picker groups tags into two sections. Governed tags appear under a Governed header with a lock icon, and everything else appears under Other. An Include system tags toggle shows or hides system tags.

    Checkpoint 3 of 7· Put it in order

    Put the Catalog Explorer steps for tagging a table in order

    1. 1.Click Catalog in the sidebar
    2. 2.On the object's Overview page, under Tags, click Add tags (or the Add/Edit tags icon)
    3. 3.Select an existing tag key and value, or enter a new tag
    4. 4.Select the securable object

    Sources1

    3.Governed tags, system tags and the certification badge

    Not every tag in the picker behaves the same way. A governed tag is an account-level tag with a tag policy. The policy defines the allowed values and controls which users and groups can assign the tag. Two things change for the person applying it. First, the value must come from the policy's list. Second, you need the ASSIGN permission on that governed tag in addition to the normal tagging privileges. Deleting a governed tag does not remove it from objects. The assignments stay in place but become ungoverned, so anyone can modify them without the extra permission.

    System tags are a special type of governed tag whose keys and values are predefined by Databricks. Users cannot modify or delete them, but governed tag permissions still control who can assign them. For a data analyst, the most important one is system.certification_status. It has exactly two values: certified, meaning the asset meets internal standards for accuracy, completeness and trust, and deprecated, meaning it is outdated and should not be used in new work. The badge appears next to the object's name, and the tag affects how the data appears in notebooks and the SQL editor.

    The three kinds of tag you meet in the Catalog Explorer tag picker
    Tag kindUI markerWho defines keys and valuesWhat you need to assign it
    Ungoverned tagListed under OtherWhoever applies itOwnership, or APPLY TAG + USE SCHEMA + USE CATALOG
    Governed tagLock icon, listed under GovernedThe tag policy (allowed values)The tagging privileges plus ASSIGN on the governed tag
    System tag (e.g. system.certification_status)Wrench icon, shown via Include system tagsDatabricks; users cannot modify or delete itControlled through governed tag permission settings

    Checkpoint 4 of 7· Match them up

    Match each icon you see in Catalog Explorer to what it tells you

    Tap a term, then the definition that fits it.

    Checkpoint 5 of 7· Exam question

    A data steward already has `USE CATALOG` and `USE SCHEMA` on the `sales` catalog and schema. In Catalog Explorer, they try adding the governed tag `data_classification = restricted` to the `customers` table, and the assignment fails, even though `restricted` is a listed allowed value for that tag. What most likely explains the failure?

    Sources123

    4.Tagging with SQL, and the limits that apply

    Anything you can do in the Tags area of the UI you can also do in SQL. On Databricks Runtime 16.1 and above, the SET TAG and UNSET TAG statements manage tags on securable objects. The example below tags a catalog with a cost center.

    SET TAG (Runtime 16.1+) applying a key and value to a catalogsql
    SET TAG ON CATALOG catalog `cost_center` = `hr`;

    On Runtime 13.3 and above, the older form is an ALTER statement with a SET TAGS or UNSET TAGS clause. The documentation uses it to put a governed tag on a single column:

    Checkpoint 6 of 7· Fill the gap

    Which keyword completes this statement that tags the SSN column?

    -- Add the governed tag to ssn column
    ALTER TABLE abac.customers.profiles
    ALTER COLUMN SSN
    SET  ?  ('pii' = 'ssn');

    Whichever method you use, the same constraints apply. Tag keys are case sensitive, so Sales and sales are different tags. An object can carry at most 50 tags, and a table can have at most 1,000 column tags across all its columns. Keys and values are limited to 256 characters each, and neither may have leading or trailing spaces. Keys cannot contain the characters . , - = / : . You also cannot tag several columns in one ALTER TABLE command; each column needs its own statement. COMMENT is different here, because it does accept several columns at once. To read tags back, query the INFORMATION_SCHEMA views CATALOG_TAGS, SCHEMA_TAGS, TABLE_TAGS, COLUMN_TAGS and VOLUME_TAGS.

    The documentation gives a fixed order for this, meant to prevent potential data leaks. First remove the tag with UNSET TAG ON COLUMN, then drop the column with ALTER TABLE ... DROP COLUMN. Dropping the column does not by itself erase the data, because time travel might still expose it. To delete the data permanently, follow the separate Drop columns procedure. Foreign tables are the one exception: their column tags are dropped automatically when the column is dropped in the foreign source.

    Checkpoint 7 of 7· Put it in order

    Put the steps for removing a column that carries a governed tag, and permanently deleting its data, in order

    1. 1.ALTER TABLE <catalog>.<schema>.<table> DROP COLUMN <column>
    2. 2.Follow the Drop columns steps to permanently delete the column's data
    3. 3.UNSET TAG ON COLUMN <catalog>.<schema>.<table>.<column> <tag_key>

    Sources1

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Deleting a governed tag removes that tag from every object that carried it.Why is that wrong?

      The tag assignments stay on the objects but become ungoverned, so anyone can then modify them without the governed-tag permission.

      Covered in Governed tags, system tags and the certification badge

    2. 2.Tag keys are case-insensitive, so 'Sales' and 'sales' are the same tag.Why is that wrong?

      Tag keys are case sensitive, and those two keys are distinct tags.

      Covered in Tagging with SQL, and the limits that apply

    3. 3.Like COMMENT, one ALTER TABLE statement can set tags on several columns at once.Why is that wrong?

      Each column must be tagged separately. COMMENT is the clause that accepts multiple columns.

      Covered in Tagging with SQL, and the limits that apply

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Using tags also simplifies the search and discovery of tables and views using the workspace search functionality.”
      ↩︎ What a tag is and what you can tag
      “Securable object tagging is currently supported on catalogs, schemas, tables, table columns, volumes, views, functions, registered models, model versions”
      ↩︎ What a tag is and what you can tag
      “Tag search requires exact term matching.”
      ↩︎ What a tag is and what you can tag
      “USE SCHEMA on the object's parent schema”
      ↩︎ Adding a tag in Catalog Explorer
      “Tag keys are required. Whether a tag value is required depends on the tag key.”
      ↩︎ Adding a tag in Catalog Explorer
      “To add a governed tag to Unity Catalog securable objects, you must also have the ASSIGN permission on the governed tag.”
      ↩︎ Governed tags, system tags and the certification badge
      “System tags are a special type of governed tag that are predefined by Databricks.”
      ↩︎ Governed tags, system tags and the certification badge
      “You can assign a maximum of 50 tags to a single securable object (table or column).”
      ↩︎ Tagging with SQL, and the limits that apply
      “You cannot assign tags to multiple columns in a single ALTER TABLE command.”
      ↩︎ Tagging with SQL, and the limits that apply
      “Otherwise, time travel might expose the data.”
      ↩︎ Tagging with SQL, and the limits that apply
      “The tags remain on objects, but anyone can assign or modify them without requiring permissions.”
      ↩︎ Exam trap 1
      “Tag keys are case sensitive. For example, Sales and sales are two distinct tags.”
      ↩︎ Exam trap 2
      “This differs from the COMMENT clause, which does support multiple columns in one command.”
      ↩︎ Exam trap 3
      “do not use tag names, values or descriptors that contain personal or sensitive information”
      ↩︎ Checkpoint
      “To add tags to Unity Catalog securable objects, you must own the object or have all of the following privileges:”
      ↩︎ Checkpoint
      “On the object Overview page, under Tags, add or update a tag”
      ↩︎ Checkpoint
      “When you drop a column that has one or more governed tags assigned, the drop operation fails.”
      ↩︎ Prediction
      “To drop a tagged column, you must first remove all governed tags from it.”
      ↩︎ Checkpoint
    2. 2.
      “It is a system-governed tag with two tag values: certified and deprecated.”
      ↩︎ Governed tags, system tags and the certification badge
      “The tag is displayed next to object names in the workspace, and influences how data appears in notebooks and the SQL editor.”
      ↩︎ Governed tags, system tags and the certification badge
    3. 3.
      “Governed tags are marked with a lock icon and grouped under Governed in the tag assignment dropdown.”
      ↩︎ Governed tags, system tags and the certification badge
      “Certified assets display a check mark in Catalog Explorer; deprecated assets display a restricted icon.”
      ↩︎ Checkpoint

    Also cited

    Continue to page 2 of 2

    View Data Lineage in Catalog Explorer

    Spotted a mistake, or was something unclear? Tell us.