Tags & Data Governance
Tags classify tables and columns with governance metadata, enabling systematic data management across your organization. By associating masking policies, access rules, and compliance labels with tags, you can enforce governance policies consistently across all tagged objects without managing each table individually.
Creating Tags
A tag is a named governance label that can be assigned to tables, schemas, or individual columns. Tags can optionally restrict their values to a predefined set.
-- Create a tag with no value restrictions
CREATE TAG cost_center;
-- Create a tag with allowed values
CREATE TAG pii_level ALLOWED_VALUES = ('public', 'internal', 'confidential', 'restricted');
-- Create a tag with a comment
CREATE TAG data_owner COMMENT = 'Department or team responsible for this data asset';
When ALLOWED_VALUES is specified, any attempt to assign a value not in the list will be rejected.
Assigning Tags
Tags can be assigned to tables, views, and individual columns. Each object can have multiple tags, and each tag assignment carries a string value.
Table-Level Tags
-- Tag a table
ALTER TABLE sales.orders SET TAG cost_center = 'sales-ops';
ALTER TABLE sales.orders SET TAG data_owner = 'sales-engineering';
-- Tag a view
ALTER VIEW analytics.revenue_summary SET TAG data_owner = 'analytics-team';
Column-Level Tags
-- Tag individual columns
ALTER TABLE customers ALTER COLUMN email SET TAG pii_level = 'confidential';
ALTER TABLE customers ALTER COLUMN phone SET TAG pii_level = 'confidential';
ALTER TABLE customers ALTER COLUMN name SET TAG pii_level = 'internal';
ALTER TABLE customers ALTER COLUMN customer_id SET TAG pii_level = 'public';
Schema-Level Tags
-- Tag an entire schema (applies to all objects within)
ALTER SCHEMA raw_data SET TAG pii_level = 'restricted';
Removing Tags
-- Remove a tag from a table
ALTER TABLE sales.orders UNSET TAG cost_center;
-- Remove a tag from a column
ALTER TABLE customers ALTER COLUMN email UNSET TAG pii_level;
Tag-Based Masking
Tags can be associated with masking policies, so that any column carrying a specific tag value is automatically masked according to the policy. This eliminates the need to apply masking policies to each column individually.
-- Create a masking policy
CREATE MASKING POLICY mask_confidential AS (val STRING)
RETURNS STRING ->
CASE
WHEN CURRENT_ROLE() IN ('ADMIN', 'DATA_ENGINEER') THEN val
ELSE '***MASKED***'
END;
-- Associate the masking policy with a tag value
ALTER TAG pii_level SET MASKING POLICY mask_confidential ON 'confidential';
After this association, every column tagged with pii_level = 'confidential' is automatically masked for users who do not hold the ADMIN or DATA_ENGINEER role. When a new column is tagged with the same value, the masking policy applies immediately without additional configuration.
Multiple Masking Levels
-- Different masking for different PII levels
CREATE MASKING POLICY mask_internal AS (val STRING)
RETURNS STRING ->
CASE
WHEN CURRENT_ROLE() IN ('ADMIN', 'DATA_ENGINEER', 'ANALYST') THEN val
ELSE LEFT(val, 1) || '***'
END;
ALTER TAG pii_level SET MASKING POLICY mask_internal ON 'internal';
ALTER TAG pii_level SET MASKING POLICY mask_confidential ON 'confidential';
Discovery
Listing Tags
-- List all tags in the current schema
SHOW TAGS;
-- List all tags in a specific database
SHOW TAGS IN DATABASE analytics;
Finding Tag References
-- Find all objects tagged with a specific tag
SHOW TAG REFERENCES TAG_NAME = 'pii_level';
-- Find all objects with a specific tag value
SHOW TAG REFERENCES TAG_NAME = 'pii_level' TAG_VALUE = 'confidential';
The output includes the object name, object type (TABLE, COLUMN, SCHEMA), tag value, and the database/schema path.
Governance Patterns
PII Classification
Classify columns by sensitivity level and apply automatic masking:
-- Define the classification tag
CREATE TAG pii_level ALLOWED_VALUES = ('public', 'internal', 'confidential', 'restricted');
-- Tag columns across your data model
ALTER TABLE users ALTER COLUMN ssn SET TAG pii_level = 'restricted';
ALTER TABLE users ALTER COLUMN email SET TAG pii_level = 'confidential';
ALTER TABLE users ALTER COLUMN city SET TAG pii_level = 'internal';
ALTER TABLE users ALTER COLUMN user_id SET TAG pii_level = 'public';
-- Associate masking policies with each level
ALTER TAG pii_level SET MASKING POLICY mask_restricted ON 'restricted';
ALTER TAG pii_level SET MASKING POLICY mask_confidential ON 'confidential';
ALTER TAG pii_level SET MASKING POLICY mask_internal ON 'internal';
Data Ownership
Track which team owns each data asset:
CREATE TAG data_owner;
ALTER TABLE sales.orders SET TAG data_owner = 'sales-engineering';
ALTER TABLE analytics.sessions SET TAG data_owner = 'analytics-team';
ALTER TABLE finance.invoices SET TAG data_owner = 'finance-ops';
-- Find all tables owned by a specific team
SHOW TAG REFERENCES TAG_NAME = 'data_owner' TAG_VALUE = 'sales-engineering';
Regulatory Compliance
Tag columns with applicable regulatory requirements:
CREATE TAG compliance ALLOWED_VALUES = ('GDPR', 'HIPAA', 'PCI', 'SOX');
ALTER TABLE patients ALTER COLUMN diagnosis SET TAG compliance = 'HIPAA';
ALTER TABLE payments ALTER COLUMN card_number SET TAG compliance = 'PCI';
ALTER TABLE users ALTER COLUMN email SET TAG compliance = 'GDPR';
-- Audit: find all PCI-tagged columns
SHOW TAG REFERENCES TAG_NAME = 'compliance' TAG_VALUE = 'PCI';
Auto-Masking with Tags
Combine classification tags with masking policies to enforce governance at scale. When new tables or columns are tagged, the appropriate masking is applied automatically:
-- Any column tagged pii_level='restricted' is now fully masked
-- Any column tagged pii_level='confidential' is partially masked
-- No per-column masking policy assignments needed
Tag Propagation
Tags on tables propagate to audit logs for all queries that read those tables. When a query accesses a table tagged with pii_level = 'restricted', the audit log entry includes that tag, enabling compliance teams to track access to sensitive data across all queries without inspecting individual column-level tags.
Managing Tags
-- Modify allowed values for an existing tag
ALTER TAG pii_level SET ALLOWED_VALUES = ('public', 'internal', 'confidential', 'restricted', 'top-secret');
-- Add a comment to a tag
ALTER TAG data_owner SET COMMENT = 'Updated ownership tracking tag';
-- Drop a tag (removes all assignments)
DROP TAG cost_center;
Dropping a tag removes all of its assignments across all objects. Associated masking policies are unlinked but not dropped.