What you will be able to do
- Create tags, limit their values, and set them on objects and columns with CREATE … WITH TAG and ALTER … SET TAG
- Choose a PROPAGATE setting and use apply_method to tell how a tag got onto an object
- Explain how sensitive data classification assigns semantic and privacy categories through system tags and tag maps
- Check which databases classification covers and where its cost shows up
Key concept
Tag as queryable governance metadata — A tag is a schema-level key-value label that you attach to accounts, warehouses, tables, columns and other objects. Snowflake can attach tags on its own through inheritance, propagation and classification. Because tag assignments can be queried, they let you monitor sensitive data, usage and cost.
1.What a tag is and where you can set it
A tag is a schema-level object. Its name must be unique within its schema. When you assign it to another object you give it a string value, and Snowflake stores the pair as a key and a value. One tag can be set on many object types at once, for example a warehouse and a table. Many tables can share one value, such as cost_center = 'sales', or each can have its own.
Tags are inherited down the securable object hierarchy. A tag on an account flows to its warehouses, and a tag on a table flows to every column in it. This is why tagging works for governance: once you tag tables, views and columns and then query those tags, you can find every object holding sensitive information. Data stewards can then decide how to protect that data. Tags on warehouses do a different job: they group resource usage by cost center or project.
You can set a tag when you create an object (CREATE WAREHOUSE mywarehouse WITH TAG (cost_center = 'sales');) or later (ALTER WAREHOUSE wh1 SET TAG cost_center = 'sales';). For columns, use CREATE TABLE, CREATE VIEW, ALTER TABLE … MODIFY COLUMN, or ALTER VIEW. Snowflake suggests two ways to manage tags. In a centralized approach, a tag_admin custom role both creates and applies tags. In a decentralized approach, tag_admin creates the tags so names stay consistent, and individual teams apply them. In the centralized example, the role gets CREATE TAG on a schema and the global APPLY TAG privilege on the account.
There are quotas. One object can carry at most 50 tags. Separately, all the columns of one table combined can carry at most 50 *different* tags.
CREATE TABLE t1 (
COL1 INT WITH TAG (tag1='col1', tag2='col1'),
COL2 INT WITH TAG (tag1='col2')
)
WITH TAG (tag3='t1');Checkpoint 1 of 5· Check yourself
After the CREATE TABLE t1 statement above, how many more distinct tags can be set on the columns of t1?
The 50-tag column limit counts distinct tags across all columns. tag1 and tag2 use two slots, which leaves 48. The table-level tag3 counts against the separate table limit.
“Set 48 more tags on the columns of t1. The limit is on different tags, so tag1 isn’t counted twice.”Source: docs.snowflake.com
Sources1
2.Controlling tag values and automatic propagation
Free-text values cause drift: one team writes Finance, another writes fin. The ALLOWED_VALUES parameter limits a tag to a fixed list of values. A tag can have up to 5,000 values, and each value can be up to 256 characters. Use ALTER TAG … ADD ALLOWED_VALUES or DROP ALLOWED_VALUES to change the list, and call SYSTEM$GET_TAG_ALLOWED_VALUES to see it.
CREATE TAG cost_center ALLOWED_VALUES 'finance', 'engineering';The PROPAGATE parameter makes a tag follow data and dependencies automatically, so a sensitivity label on a source also reaches what is built from it. If propagation is on, the order of values in the allowed list can decide which value wins when propagated values conflict. Creating and setting tags works on every edition. Tag propagation and tag-based masking policies require Enterprise Edition or higher.
| PROPAGATE value | Tag is propagated when… |
|---|---|
| ON_DEPENDENCY | a target object depends on the source object |
| ON_DATA_MOVEMENT | data moves from the source object to the target object |
| ON_DEPENDENCY_AND_DATA_MOVEMENT | either of the above happens |
| (UNSET PROPAGATE) | propagation is turned off |
Checkpoint 2 of 5· Fill the gap
Complete the statement so the tag propagates to a view built on a tagged table. Data movement such as CTAS should not trigger it.
CREATE TAG data_sensitivity PROPAGATE = ? ;A view built on a table is an object dependency, so ON_DEPENDENCY covers it without covering data movement. ON_REFERENCE and INHERIT are not PROPAGATE values.
Source: docs.snowflake.com3.Monitoring tags: how did this tag get here?
Snowflake can attach a tag in five ways. Someone sets it manually with CREATE or ALTER. The object inherits it from higher in the hierarchy. It propagates from an object this one depends on, or from an object whose data moved here. Classification sets it on a column found to hold sensitive data. Or it comes along when a table is created with CREATE TABLE … LIKE or CREATE TABLE … CLONE.
When you audit tags, the method usually matters as much as the value. A propagated sensitivity tag tells you the data came from a sensitive source. Several views and functions expose an apply_method column that records how each tag was attached: the ACCOUNT_USAGE.TAG_REFERENCES view, the INFORMATION_SCHEMA.TAG_REFERENCES and TAG_REFERENCES_ALL_COLUMNS functions, and ACCOUNT_USAGE.TAG_REFERENCES_WITH_LINEAGE.
SELECT tag_name, tag_value, apply_method, level, domain FROM TABLE(my_db.INFORMATION_SCHEMA.TAG_REFERENCES('my_table', 'TABLE'));Snowsight also has a Governance & security » Tags & policies area with a dashboard and a Tagged Objects tab for filtering. It needs Enterprise Edition or higher, plus either ACCOUNTADMIN or a role granted the GOVERNANCE_VIEWER and OBJECT_VIEWER database roles.
Checkpoint 3 of 5· Check yourself
A tagged table orders is copied with a CTAS statement into orders_copy. The tag is configured to propagate, and orders_copy ends up with the tag. Which association method explains this?
CTAS moves data from a tagged object into a new one, which is the data-movement case of automatic propagation. Inheritance only flows from parent to child in the hierarchy, such as from a table to its columns.
“when data moves from a tagged object to another object (for example, using a CTAS statement to create a table)”Source: docs.snowflake.com
4.Sensitive data classification: tags applied for you
Manual tagging only works if someone already knows where the sensitive data is. Sensitive data classification finds it automatically. Each column classified as sensitive gets two labels. The semantic category says what kind of personal attribute it is, such as a name, an address or a national identifier. Snowflake provides native categories, and you can add custom ones. The privacy category says how sensitive it is: IDENTIFIER, QUASI_IDENTIFIER or SENSITIVE.
Snowflake records these results as two system-defined tags, SNOWFLAKE.CORE.SEMANTIC_CATEGORY and SNOWFLAKE.CORE.PRIVACY_CATEGORY. A tag map links your own tags to these system tags. For example, whenever SEMANTIC_CATEGORY = 'NAME' is applied, Snowflake also applies tag_db.sch.pii = 'Highly confidential'. As a result, your existing tag-driven monitoring picks up newly found sensitive columns without extra work.
Classification settings are saved in a classification profile. You can create one in the Trust Center or with SQL. With SQL, associating the profile with a database to start classification is a separate step. A profile can also turn on AI mode, which uses the openai-gpt-5-mini model to find more semantic categories. Tags lead directly to protection: if a tag-based masking policy is attached to a user-defined tag, columns are masked as soon as classification applies that tag. This works for new data as it arrives.
Checkpoint 4 of 5· Match them up
Match each classification term to what it does
Tap a term, then the definition that fits it.
The two categories are stored as system tags. A tag map turns them into your own tags, and the profile holds the settings that drive classification.
“every column that is identified as containing sensitive data is assigned two categories: a semantic category and a privacy category.”Source: docs.snowflake.com
Sources3
5.Monitoring what classification covers and costs
Using classification to monitor data starts with knowing what is being classified. When a database is associated with a classification profile, Snowflake classifies all the tables and views in it automatically. One caveat: views are excluded by default. In Snowsight, go to Governance & security » Trust Center, then Data Security, then Dashboard, and find the *Databases monitored by classification* tile. It lists databases as Monitored or Partially monitored. A database is *partially monitored* when someone used SQL to set a profile on a schema instead of on the whole database. To get the same list in SQL:
SELECT SYSTEM$SHOW_SENSITIVE_DATA_MONITORED_ENTITIES('DATABASE');Classification runs on serverless compute and consumes credits. AI mode adds token charges on top. Classifying a view can cost more than classifying a table, depending on how complex the view's query is. Materialized views don't carry this extra cost. To see spending, open Admin » Cost management, choose Consumption, and filter by the *Sensitive Data Classification* service type. You can also query METERING_HISTORY in ACCOUNT_USAGE.
Checkpoint 5 of 5· Check yourself
The Trust Center dashboard shows the database SALES as 'Partially monitored'. What is the most likely cause?
'Partially monitored' means a profile was set by SQL on a schema rather than on the database. It says nothing about failures or AI mode.
“A database is partially monitored if someone used SQL to set a classification profile directly on a schema in the database”Source: docs.snowflake.com
Sources3
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Object tagging as a whole requires Enterprise Edition.Why is that wrong?
Any edition can create and set tags. Only advanced features, namely tag propagation and tag-based masking policies, require Enterprise Edition or higher.
2.Associating a database with a classification profile means every view in it is classified too.Why is that wrong?
Views are left out of classification unless you include them, partly because classifying a view can cost more than classifying a table.
3.Creating a classification profile with SQL starts classification right away.Why is that wrong?
With SQL, associating the profile with a database is a separate step, and that step is what starts classification.
Covered in Sensitive data classification: tags applied for you
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“setting a tag and then querying the tag enables the discovery of a multitude of database objects and columns that contain sensitive information.”
↩︎ What a tag is and where you can set it“if a tag is set on a table, the tag will be inherited by all columns in that table.”
↩︎ What a tag is and where you can set it“You can set a maximum of 50 tags on a single object, including tables and views.”
↩︎ What a tag is and where you can set it“Your account must be Enterprise Edition or higher to use the following capabilities:”
↩︎ Controlling tag values and automatic propagation“The following views and functions include the apply_method column, which shows how a tag was associated with an object.”
↩︎ Monitoring tags: how did this tag get here?“you can query them to monitor usage on objects and facilitate data governance operations, such as auditing and reporting.”
↩︎ Key concept“Creating and setting tags is available to all accounts.”
↩︎ Exam trap 1“Set 48 more tags on the columns of t1. The limit is on different tags, so tag1 isn’t counted twice.”
↩︎ Checkpoint“when data moves from a tagged object to another object (for example, using a CTAS statement to create a table)”
↩︎ Checkpoint - 2.
“The maximum number of possible string values for a single tag is 5,000.”
↩︎ Controlling tag values and automatic propagation“To access the Tags & policies area, your Snowflake account must be Enterprise Edition or higher.”
↩︎ Monitoring tags: how did this tag get here?“Changing or removing an allowed value from a tag’s definition doesn’t affect tag values already assigned to objects.”
↩︎ Prediction - 3.
“You can map user-defined tags to system-defined classification tags.”
↩︎ Sensitive data classification: tags applied for you“the data will be automatically masked when Snowflake applies the tag as part of the classification process.”
↩︎ Sensitive data classification: tags applied for you“If a database is associated with a classification profile, all the tables and views in that database are being automatically classified”
↩︎ Monitoring what classification covers and costs“Sensitive data classification consumes credits as it uses serverless compute resources to classify tables in the database.”
↩︎ Monitoring what classification covers and costs“By default, views are excluded from classification.”
↩︎ Exam trap 2“If you are using SQL, associating the classification profile with a database to start the classification process is a separate step.”
↩︎ Exam trap 3“every column that is identified as containing sensitive data is assigned two categories: a semantic category and a privacy category.”
↩︎ Checkpoint“A database is partially monitored if someone used SQL to set a classification profile directly on a schema in the database”
↩︎ Checkpoint