CertSafari
    Snowflake SnowPro Advanced: Data Engineer (DEA-C02)· Lessons

    Domain 4 · Lesson 14/22

    Snowflake Object Tagging and Sensitive Data Classification

    Monitor data.

    10 min read
    7% of exam
    3 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Create tags, limit their values, and set them on objects and columns with CREATE … WITH TAG and ALTER … SET TAG
    • Choose a PROPAGATE setting and use apply_method to tell how a tag got onto an object
    • Explain how sensitive data classification assigns semantic and privacy categories through system tags and tag maps
    • Check which databases classification covers and where its cost shows up

    Key concept

    Tag as queryable governance metadata — A tag is a schema-level key-value label that you attach to accounts, warehouses, tables, columns and other objects. Snowflake can attach tags on its own through inheritance, propagation and classification. Because tag assignments can be queried, they let you monitor sensitive data, usage and cost.

    1.What a tag is and where you can set it

    A tag is a schema-level object. Its name must be unique within its schema. When you assign it to another object you give it a string value, and Snowflake stores the pair as a key and a value. One tag can be set on many object types at once, for example a warehouse and a table. Many tables can share one value, such as cost_center = 'sales', or each can have its own.

    Tags are inherited down the securable object hierarchy. A tag on an account flows to its warehouses, and a tag on a table flows to every column in it. This is why tagging works for governance: once you tag tables, views and columns and then query those tags, you can find every object holding sensitive information. Data stewards can then decide how to protect that data. Tags on warehouses do a different job: they group resource usage by cost center or project.

    You can set a tag when you create an object (CREATE WAREHOUSE mywarehouse WITH TAG (cost_center = 'sales');) or later (ALTER WAREHOUSE wh1 SET TAG cost_center = 'sales';). For columns, use CREATE TABLE, CREATE VIEW, ALTER TABLE … MODIFY COLUMN, or ALTER VIEW. Snowflake suggests two ways to manage tags. In a centralized approach, a tag_admin custom role both creates and applies tags. In a decentralized approach, tag_admin creates the tags so names stay consistent, and individual teams apply them. In the centralized example, the role gets CREATE TAG on a schema and the global APPLY TAG privilege on the account.

    There are quotas. One object can carry at most 50 tags. Separately, all the columns of one table combined can carry at most 50 *different* tags.

    Tags set on the table and on its columns. The table-level and column-level limits are counted separately.sql
    CREATE TABLE t1 (
      COL1 INT WITH TAG (tag1='col1', tag2='col1'),
      COL2 INT WITH TAG (tag1='col2')
      )
      WITH TAG (tag3='t1');

    Checkpoint 1 of 5· Check yourself

    After the CREATE TABLE t1 statement above, how many more distinct tags can be set on the columns of t1?

    Sources1

    2.Controlling tag values and automatic propagation

    Free-text values cause drift: one team writes Finance, another writes fin. The ALLOWED_VALUES parameter limits a tag to a fixed list of values. A tag can have up to 5,000 values, and each value can be up to 256 characters. Use ALTER TAG … ADD ALLOWED_VALUES or DROP ALLOWED_VALUES to change the list, and call SYSTEM$GET_TAG_ALLOWED_VALUES to see it.

    A tag that accepts only two valuessql
    CREATE TAG cost_center ALLOWED_VALUES 'finance', 'engineering';

    The PROPAGATE parameter makes a tag follow data and dependencies automatically, so a sensitivity label on a source also reaches what is built from it. If propagation is on, the order of values in the allowed list can decide which value wins when propagated values conflict. Creating and setting tags works on every edition. Tag propagation and tag-based masking policies require Enterprise Edition or higher.

    PROPAGATE values and when each one propagates a tag
    PROPAGATE valueTag is propagated when…
    ON_DEPENDENCYa target object depends on the source object
    ON_DATA_MOVEMENTdata moves from the source object to the target object
    ON_DEPENDENCY_AND_DATA_MOVEMENTeither of the above happens
    (UNSET PROPAGATE)propagation is turned off

    Checkpoint 2 of 5· Fill the gap

    Complete the statement so the tag propagates to a view built on a tagged table. Data movement such as CTAS should not trigger it.

    CREATE TAG data_sensitivity PROPAGATE =  ? ;

    Sources21

    3.Monitoring tags: how did this tag get here?

    Snowflake can attach a tag in five ways. Someone sets it manually with CREATE or ALTER. The object inherits it from higher in the hierarchy. It propagates from an object this one depends on, or from an object whose data moved here. Classification sets it on a column found to hold sensitive data. Or it comes along when a table is created with CREATE TABLE … LIKE or CREATE TABLE … CLONE.

    When you audit tags, the method usually matters as much as the value. A propagated sensitivity tag tells you the data came from a sensitive source. Several views and functions expose an apply_method column that records how each tag was attached: the ACCOUNT_USAGE.TAG_REFERENCES view, the INFORMATION_SCHEMA.TAG_REFERENCES and TAG_REFERENCES_ALL_COLUMNS functions, and ACCOUNT_USAGE.TAG_REFERENCES_WITH_LINEAGE.

    Check whether each tag on a table was set manually or arrived another waysql
    SELECT tag_name, tag_value, apply_method, level, domain FROM TABLE(my_db.INFORMATION_SCHEMA.TAG_REFERENCES('my_table', 'TABLE'));

    Snowsight also has a Governance & security » Tags & policies area with a dashboard and a Tagged Objects tab for filtering. It needs Enterprise Edition or higher, plus either ACCOUNTADMIN or a role granted the GOVERNANCE_VIEWER and OBJECT_VIEWER database roles.

    Checkpoint 3 of 5· Check yourself

    A tagged table orders is copied with a CTAS statement into orders_copy. The tag is configured to propagate, and orders_copy ends up with the tag. Which association method explains this?

    Sources12

    4.Sensitive data classification: tags applied for you

    Manual tagging only works if someone already knows where the sensitive data is. Sensitive data classification finds it automatically. Each column classified as sensitive gets two labels. The semantic category says what kind of personal attribute it is, such as a name, an address or a national identifier. Snowflake provides native categories, and you can add custom ones. The privacy category says how sensitive it is: IDENTIFIER, QUASI_IDENTIFIER or SENSITIVE.

    Snowflake records these results as two system-defined tags, SNOWFLAKE.CORE.SEMANTIC_CATEGORY and SNOWFLAKE.CORE.PRIVACY_CATEGORY. A tag map links your own tags to these system tags. For example, whenever SEMANTIC_CATEGORY = 'NAME' is applied, Snowflake also applies tag_db.sch.pii = 'Highly confidential'. As a result, your existing tag-driven monitoring picks up newly found sensitive columns without extra work.

    Classification settings are saved in a classification profile. You can create one in the Trust Center or with SQL. With SQL, associating the profile with a database to start classification is a separate step. A profile can also turn on AI mode, which uses the openai-gpt-5-mini model to find more semantic categories. Tags lead directly to protection: if a tag-based masking policy is attached to a user-defined tag, columns are masked as soon as classification applies that tag. This works for new data as it arrives.

    Checkpoint 4 of 5· Match them up

    Match each classification term to what it does

    Tap a term, then the definition that fits it.

    Sources3

    5.Monitoring what classification covers and costs

    Using classification to monitor data starts with knowing what is being classified. When a database is associated with a classification profile, Snowflake classifies all the tables and views in it automatically. One caveat: views are excluded by default. In Snowsight, go to Governance & security » Trust Center, then Data Security, then Dashboard, and find the *Databases monitored by classification* tile. It lists databases as Monitored or Partially monitored. A database is *partially monitored* when someone used SQL to set a profile on a schema instead of on the whole database. To get the same list in SQL:

    List the databases associated with a classification profilesql
    SELECT SYSTEM$SHOW_SENSITIVE_DATA_MONITORED_ENTITIES('DATABASE');

    Classification runs on serverless compute and consumes credits. AI mode adds token charges on top. Classifying a view can cost more than classifying a table, depending on how complex the view's query is. Materialized views don't carry this extra cost. To see spending, open Admin » Cost management, choose Consumption, and filter by the *Sensitive Data Classification* service type. You can also query METERING_HISTORY in ACCOUNT_USAGE.

    Checkpoint 5 of 5· Check yourself

    The Trust Center dashboard shows the database SALES as 'Partially monitored'. What is the most likely cause?

    Sources3

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Object tagging as a whole requires Enterprise Edition.Why is that wrong?

      Any edition can create and set tags. Only advanced features, namely tag propagation and tag-based masking policies, require Enterprise Edition or higher.

      Covered in Controlling tag values and automatic propagation

    2. 2.Associating a database with a classification profile means every view in it is classified too.Why is that wrong?

      Views are left out of classification unless you include them, partly because classifying a view can cost more than classifying a table.

      Covered in Monitoring what classification covers and costs

    3. 3.Creating a classification profile with SQL starts classification right away.Why is that wrong?

      With SQL, associating the profile with a database is a separate step, and that step is what starts classification.

      Covered in Sensitive data classification: tags applied for you

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “setting a tag and then querying the tag enables the discovery of a multitude of database objects and columns that contain sensitive information.”
      ↩︎ What a tag is and where you can set it
      “if a tag is set on a table, the tag will be inherited by all columns in that table.”
      ↩︎ What a tag is and where you can set it
      “You can set a maximum of 50 tags on a single object, including tables and views.”
      ↩︎ What a tag is and where you can set it
      “Your account must be Enterprise Edition or higher to use the following capabilities:”
      ↩︎ Controlling tag values and automatic propagation
      “The following views and functions include the apply_method column, which shows how a tag was associated with an object.”
      ↩︎ Monitoring tags: how did this tag get here?
      “you can query them to monitor usage on objects and facilitate data governance operations, such as auditing and reporting.”
      ↩︎ Key concept
      “Creating and setting tags is available to all accounts.”
      ↩︎ Exam trap 1
      “Set 48 more tags on the columns of t1. The limit is on different tags, so tag1 isn’t counted twice.”
      ↩︎ Checkpoint
      “when data moves from a tagged object to another object (for example, using a CTAS statement to create a table)”
      ↩︎ Checkpoint
    2. 2.
      “The maximum number of possible string values for a single tag is 5,000.”
      ↩︎ Controlling tag values and automatic propagation
      “To access the Tags & policies area, your Snowflake account must be Enterprise Edition or higher.”
      ↩︎ Monitoring tags: how did this tag get here?
      “Changing or removing an allowed value from a tag’s definition doesn’t affect tag values already assigned to objects.”
      ↩︎ Prediction
    3. 3.
      “You can map user-defined tags to system-defined classification tags.”
      ↩︎ Sensitive data classification: tags applied for you
      “the data will be automatically masked when Snowflake applies the tag as part of the classification process.”
      ↩︎ Sensitive data classification: tags applied for you
      “If a database is associated with a classification profile, all the tables and views in that database are being automatically classified”
      ↩︎ Monitoring what classification covers and costs
      “Sensitive data classification consumes credits as it uses serverless compute resources to classify tables in the database.”
      ↩︎ Monitoring what classification covers and costs
      “By default, views are excluded from classification.”
      ↩︎ Exam trap 2
      “If you are using SQL, associating the classification profile with a database to start the classification process is a separate step.”
      ↩︎ Exam trap 3
      “every column that is identified as containing sensitive data is assigned two categories: a semantic category and a privacy category.”
      ↩︎ Checkpoint
      “A database is partially monitored if someone used SQL to set a classification profile directly on a schema in the database”
      ↩︎ Checkpoint

    Continue to page 2 of 2

    Snowflake Data Lineage, Access History and Data Quality Monitoring

    Spotted a mistake, or was something unclear? Tell us.