CertSafari
    Snowflake SnowPro Advanced: Security Engineer (SEA-C01)· Lessons

    Domain 2 · Lesson 9/21

    Snowflake Tag Inheritance, Propagation, Auditing and Lineage

    Configure object tagging and data classification frameworks.

    12 min read
    4.29% of exam
    6 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Tell tag inheritance apart from automatic tag propagation, and predict which tag value wins when inherited, propagated and manual values compete
    • Configure the PROPAGATE and ON_CONFLICT properties of a tag and monitor propagation events in an event table
    • Audit tag assignments with the TAG_REFERENCES view and table function, and read APPLY_METHOD to see how each tag was assigned
    • Use the Snowsight Lineage tab to trace column lineage and fix missing or mismatched tags

    Key concept

    Inheritance vs. propagation — Inheritance passes a tag down the securable object hierarchy, for example from account to schema or from table to column. Propagation passes a tag sideways along data flow, from a source object to the views and tables built from it. They are separate mechanisms with separate precedence rules, and the audit tools show them differently.

    1.Tag inheritance follows the object hierarchy

    Every tag-driven control starts from the same question: which tag value does this object or column actually carry? The first way an object can get a tag without anyone setting it directly is inheritance. Snowflake places securable objects in a hierarchy (account, database, schema, table, column), and a descendant inherits tags from its ancestors. A schema inherits tags set on its account, and a tag applied to a table also applies to the columns of that table.

    Inheritance only runs down this containment hierarchy. It does not follow data flow. In a chain like table_1 » view_1 » materialized_view_1, the materialized view inherits nothing from table_1 or view_1, because a view built on a table is not a child of that table. Moving tags along that kind of chain is what automatic propagation is for, and the next section covers it.

    An inherited value is also the weakest value an object can hold. It gives way in three cases: - Manual override: setting the tag directly on the object replaces the inherited value. For example, a column that inherits cost_center = 'sales' can be set to the more specific 'sales_na'. - Automatic propagation: a propagated value overwrites an inherited one. - Sensitive data classification: a value set by classification overwrites an inherited one.

    Checkpoint 1 of 7· Check yourself

    A tag cost_center = 'finance' is set on a schema. A table in that schema has a view built on it, and the view is in a different schema. Which objects get the tag through inheritance alone?

    Checkpoint 2 of 7· Exam question

    An auditor applied the tag `governance.tags.pii_level` at schema level on `SALES.CUSTOMERS` and asks for a list of every table and column that carries the tag, inherited ones included, across the whole account. A query against `SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCES` returns only the schema row. Which approach produces the complete list?

    Sources1

    2.Automatic propagation follows dependencies and data movement

    Propagation moves a tag from a source object to target objects created from it, so that any policies attached to the tag also apply to those targets. You turn it on with the PROPAGATE property in CREATE TAG or ALTER TAG. Only the tag owner, holding the account-level APPLY TAG privilege, can set it up. You can choose to propagate on object dependency, on data movement, or on both, and the two modes behave very differently.

    Object dependency covers creating a view, secure view, materialized view or dynamic table from a source. In this mode the link stays live. If you add a tag to the source, change its value, or remove it, Snowflake updates the targets to match, and removing the tag from the source removes it from the target too. The link depends on the source existing: once the source object is dropped, its tags no longer propagate.

    Data movement covers CTAS, CREATE DYNAMIC TABLE, and the DML commands INSERT, MERGE, UPDATE and COPY INTO. Here the tag is copied when the data moves. Later changes to the tag on the source are not carried over to the target.

    CREATE TABLE … CLONE and CREATE TABLE … LIKE ignore PROPAGATE entirely: they always copy the source's tags to the new object.

    Checkpoint 3 of 7· Check yourself

    A tag is configured with PROPAGATE for data movement only. A table t2 was created with CTAS from t1. Later, the tag value on t1 changes from 'internal' to 'confidential'. What happens to t2?

    Sources2

    3.Precedence and ON_CONFLICT resolution

    Two situations look like conflicts but are not. If the target already has a manually applied value, the manual value wins and the propagated value is skipped. If the target only has an inherited value, the propagated value wins. That gives the order manual > propagated > inherited.

    A real conflict happens when the same tag reaches one target from different source objects with different values. The tag's ON_CONFLICT property decides the outcome:

    ON_CONFLICT options for tag propagation
    SettingResulting value on the target
    Not set (default)The literal string CONFLICT
    ON_CONFLICT = '<string>'Your string, e.g. 'HIGHLY CONFIDENTIAL'
    ON_CONFLICT = ALLOWED_VALUES_SEQUENCEWhichever value appears first in the tag's ALLOWED_VALUES list
    ON_CONFLICT = MERGEA set of the conflicting values; valid only when MULTI_VALUE = TRUE

    ALLOWED_VALUES_SEQUENCE has a catch: if you reorder the allowed values, future conflicts can resolve to a different value. To watch conflicts as they happen, set ENABLE_TAG_PROPAGATION_EVENT_LOGGING. Snowflake then writes events to the event table set for the tag's database, or to the default event table if none is set. Event types are CONFLICT, PROPAGATION_SKIPPED_MANUAL_TAG, and TAG_PROPAGATION_LIMIT_EXCEEDED. The last one is logged at ERROR severity when there are more than 10,000 target objects. Events only appear if LOG_EVENT_LEVEL allows their severity.

    Enable telemetry for tag propagation eventssql
    ALTER ACCOUNT SET ENABLE_TAG_PROPAGATION_EVENT_LOGGING = TRUE;

    Checkpoint 4 of 7· Fill the gap

    You want a conflict between 'internal' and 'public' to resolve to 'internal' because it comes earlier in the allowed list. Which token completes the statement?

    CREATE TAG data_sensitivity ALLOWED_VALUES 'confidential', 'internal', 'public' PROPAGATE = ON_DEPENDENCY ON_CONFLICT =  ? ;

    Checkpoint 5 of 7· Exam question

    A view joins `HR.EMPLOYEES.SALARY_BAND` (tagged `sensitivity = 'internal'`) with `FIN.PAYROLL.BONUS` (tagged `sensitivity = 'restricted'`) in a single output column through an expression. The tag `sensitivity` propagates on dependency, and the governance team wants the stricter value to win automatically instead of the default result. The tag is created with `ALLOWED_VALUES 'public', 'internal', 'restricted'`. Which configuration meets the requirement?

    Sources2

    4.Auditing tags with TAG_REFERENCES

    With manual, inherited, propagated and classified values all in play, an audit has to show both where a tag sits and how it got there. Snowflake offers several tools, and they differ on the most testable point: whether inherited tags are included.

    The ACCOUNT_USAGE view SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCES covers the whole account but records only direct associations. It does not include inheritance, its latency can be up to two hours, and it shows only objects the current role can access. Its APPLY_METHOD column reads CLASSIFIED, MANUAL or PROPAGATED, and OBJECT_DELETED lets you filter out dropped objects.

    The Information Schema table function TAG_REFERENCES('<object_name>', '<object_domain>') looks at one object or column and does include inheritance. Its APPLY_METHOD can also be INHERITED, and a LEVEL column gives the domain where the tag is actually set. To see the system tags that sensitive data classification applies, use a role with IMPORTED PRIVILEGES on the SNOWFLAKE database.

    For an account-wide view of one tag that does include inheritance, the Account Usage table function TAG_REFERENCES_WITH_LINEAGE('<db>.<schema>.<tag>') returns both direct and inherited associations.

    The exam guide also lists a TAG_REFERENCES_HISTORY view. None of the documentation available to this lesson describes it, so its columns and behaviour are not covered here. Check the current Snowflake reference before you rely on it.

    Which tag-audit tool shows what
    ToolScopeIncludes inherited tags?
    ACCOUNT_USAGE.TAG_REFERENCES viewAll tag associations visible to the role, up to 120 min latencyNo: direct associations only
    INFORMATION_SCHEMA TAG_REFERENCES functionOne object or column, given name and domainYes: APPLY_METHOD can be INHERITED
    TAG_REFERENCES_WITH_LINEAGE functionEvery association of one named tag across the accountYes: direct and inherited
    Account-wide audit, excluding dropped objectssql
    select tag_name, tag_value, domain, object_id from snowflake.account_usage.tag_references where object_deleted is null order by tag_name, domain, object_id;
    Tags on one column, inherited ones includedsql
    select * from table(my_db.information_schema.tag_references('my_table.result', 'COLUMN'));

    Checkpoint 6 of 7· Match them up

    Match each APPLY_METHOD value to how the tag was assigned

    Tap a term, then the definition that fits it.

    Sources345

    5.Visualizing lineage and fixing tag gaps

    Audit queries list tags object by object. Lineage shows how the objects connect, which is the same flow that propagation follows. Snowflake records two kinds of lineage relationship. Data movement covers CTAS, INSERT and MERGE. Object dependency is when a view references a table without copying its data. A source is upstream of its target, and the target is downstream.

    To open it in Snowsight, go to Catalog, then Explorer, pick a table or view, and select the Lineage tab. Selecting an object shows its columns and their tags. +/- expands more objects upstream or downstream. Selecting an edge shows how the downstream object was created, including the SQL, the stored procedure or the task, if your privileges allow. Anonymous stored procedure calls don't show their details. Nodes are grouped by database and then schema, and objects you can't access are collapsed into a separate group.

    Column lineage is where governance work gets done. Hover over a column, choose View Lineage, and then choose Upstream or Downstream. The Distance column tells you how many steps away each related column is. If related columns are missing a tag or carry a different value, a banner appears. A dashed border means the tag is missing, and a yellow border means the value doesn't match. Review and Apply fixes them in one step. The side panel also flags masking problems: if multiple masking policies are assigned to the same column, it shows Policy Error.

    Checkpoint 7 of 7· Check yourself

    In the View Column Lineage dialog, a downstream column's tag is drawn with a dashed border. What does that mean, and how do you fix it in Snowsight?

    Sources6

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.A view or materialized view built on a tagged table inherits the table's tags.Why is that wrong?

      Inheritance only runs down the securable object hierarchy. Dependent objects such as views get tags through automatic propagation, not inheritance.

      Covered in Tag inheritance follows the object hierarchy

    2. 2.Every propagated tag stays in sync with the source when the source's tag value changes.Why is that wrong?

      Only dependency-based propagation is continuously updated. Tags copied through data movement, such as CTAS, INSERT, MERGE, UPDATE or COPY INTO, are not.

      Covered in Automatic propagation follows dependencies and data movement

    3. 3.SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCES lists every tag a column effectively carries, inherited ones included.Why is that wrong?

      The ACCOUNT_USAGE view records only direct associations. Use the Information Schema TAG_REFERENCES function or TAG_REFERENCES_WITH_LINEAGE to see inherited tags.

      Covered in Auditing tags with TAG_REFERENCES

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “if a tag is applied to a table, the tag gets applied to the columns in that table.”
      ↩︎ Tag inheritance follows the object hierarchy
      “The value of an inherited tag is overwritten by sensitive data classification.”
      ↩︎ Tag inheritance follows the object hierarchy
      “Tag inheritance does not include propagation to nested objects.”
      ↩︎ Key concept
      “Tag inheritance does not include propagation to nested objects.”
      ↩︎ Exam trap 1
      “A descendant of an object in the hierarchy inherits tags from its ancestors.”
      ↩︎ Checkpoint
    2. 2.
      “Only the tag owner with the account-level APPLY TAG privilege can implement automatic tag propagation.”
      ↩︎ Automatic propagation follows dependencies and data movement
      “When you execute these statements, tags from the source are always assigned to the target object.”
      ↩︎ Automatic propagation follows dependencies and data movement
      “the existing tag value takes precedence over a propagated value so there is no conflict.”
      ↩︎ Precedence and ON_CONFLICT resolution
      “changing the ALLOWED_VALUES parameter affects how conflicts are resolved.”
      ↩︎ Precedence and ON_CONFLICT resolution
      “tags applied to target objects when there is data movement are not continuously updated as tags change on the source object.”
      ↩︎ Exam trap 2
      “tags applied to target objects when there is data movement are not continuously updated as tags change on the source object.”
      ↩︎ Checkpoint
      “the propagated value takes precedence and there is no conflict.”
      ↩︎ Prediction
    3. 3.
      “The associated tag and value are the result of a direct association to an object or through tag inheritance.”
      ↩︎ Auditing tags with TAG_REFERENCES
      “INHERITED: The object inherited the tag from an object higher up in the Snowflake securable object hierarchy.”
      ↩︎ Checkpoint
    4. 4.
      “Latency for the view may be up to 120 minutes (2 hours).”
      ↩︎ Auditing tags with TAG_REFERENCES
      “This view only records the direct relationship between the object and the tag. Tag inheritance is not included in this view.”
      ↩︎ Exam trap 3
    5. 5.
      “The associated tag and Snowflake object are the result of both a direct association to an object and tag inheritance.”
      ↩︎ Auditing tags with TAG_REFERENCES
    6. 6.
      “Object dependencies, when an object references a base object but does not materialize or copy data, such as when a view references a table.”
      ↩︎ Visualizing lineage and fixing tag gaps
      “The data lineage workflow identifies tags that are missing from upstream and downstream columns and tags that have a different value.”
      ↩︎ Visualizing lineage and fixing tag gaps
      “If a tag has a dashed border, the column does not have the tag applied.”
      ↩︎ Checkpoint

    Continue to page 2 of 2

    Snowflake Sensitive Data Classification: Automatic, Custom and Manual

    Spotted a mistake, or was something unclear? Tell us.