Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Security Posture Management (DSPM)
    Using The DSPM Platform
    Managing Classification and Tagging
    Manage DSPM Data Tags

    Manage DSPM Data Tags

    Overview

    Use this article to maintain and group the Data Tag library, including the ingestion of tags from external systems.

    Data Tags group and organize classified fields and dataset objects (databases, schemas, and tables). You can use them for searching, filtering, and creating Policy Conditions.

    The Classification > Data Tags screen lists every Data Tag available in DSPM, including:

    • Built-in tags: Applied to DLP Profiles pre-selected in the default DLP Discovery Profile.
    • Custom tags: Created and curated by your organization.
    • Infrastructure tags: Ingested from external platforms such as AWS, GCP, and Snowflake.

    To apply Data Tags to classification fields, navigate to Classification > Classification Management. For more details, see:

    • Use the DSPM Classification Management Page: For field-level classification.
    • Object-Level Tagging in DSPM: For object-level classification.

    Data Tag Auto-Assignment

    When the Netskope DSPM application scans a data store, it automatically assigns Data Tags to newly classified fields based on their associated DLP Profile.

    You configure the association between Data Tags and DLP Profiles in the Classification > DLP Profiles and Rules screen. When setting up this association, the platform prompts you to choose an inheritance effect:

    • Future-only assignment: Apply the Data Tag(s) only to future fields classified by this DLP Profile (leaving current fields as-is).
    • Retroactive assignment: Also apply the Data Tag(s) to currently classified fields.

    This configuration determines whether tags are applied only going forward or also backfilled across the existing inventory.

    Dynamic Updates via DLP Profiles

    Data Tags associated with a DLP Profile maintain a dynamic, two-way relationship with classified objects. This ensures consistency across your data inventory:

    • Adding a Data Tag: If you add a Data Tag to a DLP Profile, the system automatically applies that tag to all objects and fields already classified by that specific DLP Profile.
    • Removing a Data Tag: If you remove a Data Tag from a DLP Profile, the system automatically removes that tag from all objects and fields previously classified by that specific DLP Profile.

    Tag Inheritance Behavior

    It is important to understand how tags propagate through your data hierarchy:

    • Top-Down Inheritance: When you tag a Data Store, all child objects within it (databases, schemas, tables, and fields) automatically inherit that tag.
    • Bottom-Up Visibility: When you tag a child object, the parent object reflects this inheritance. You can view these aggregated tags in the Data Store Inventory page to see which tags are contained within a data store’s datasets.

    Built-In Data Tags

    Netskope DSPM includes several built-in Data Tags and Categories ready for immediate use:

    CategoryTags
    ComplianceGDPR, CCPA, PDP, PCI, SOX
    HealthcareHIPAA-HI, HIPAA-PI
    OtherPII

    Manage Data Tags

    Perform the following actions from the Classification > Data Tags screen.

    Create Tags

    1. Click Create New Tag.
    2. Enter the following values:
    FieldValue
    Tag CategorySelect how to group this tag in filters and drop-downs. You can also create a new category here.
    Tag NameEnter a friendly name to display throughout the platform (Spaces are not permitted).
    DescriptionExplain the tag’s purpose.
    ColorSelect a color from the palette to identify the tag visually.
    1. Click Save.

    Edit Tags

    1. Click the edit icon (pencil) on any existing Tag.
    2. Make your desired changes.
    3. Click Save.

    Delete Tags

    1. Click the delete icon (trash) on an existing Tag header.
    2. Click Delete to confirm.

    Manage Tag Categories

    Create Tag Categories

    1. Open the Create or Edit Tag modal (as described above).

    2. Click the Tag Category field > select Create new category.

    3. Enter the following values:

      FieldValue
      Category NameFriendly name to display throughout the platform.
      DescriptionExplain the category’s purpose.
    4. Click Save.

    5. Continue editing or creating your Tag.

    Edit Tag Categories

    1. Click the edit icon (pencil) on the Category you wish to modify.
    2. Make your changes and click Save.

    Delete Tag Categories

    Prerequisite: You must delete all child Tags within a category before you can delete the category itself.
    1. Click the delete icon (trash) on the Tag Category header.
    2. Click Delete to confirm.

    Ingest External Tags

    Netskope DSPM supports ingesting Data Tags from the following external systems.

    Amazon Web Services (AWS)

    When onboarding AWS Accounts and Organizations, you can auto-ingest tags from the AWS Tag Editor. This triggers the following actions:

    • Creates a Data Tag Category named after the AWS Account or Organization ID.
    • Creates a Data Tag for each AWS Tag. Ingested tags are automatically adjusted to ensure uniqueness.
    These categories and tags cannot be modified within Netskope DSPM. Update them directly in the AWS console; changes sync regularly to Netskope DSPM.

    Google Cloud Platform (GCP)

    When onboarding GCP Projects, you can auto-ingest available GCP Policy Taxonomies. This triggers the following actions:

    • Creates a Data Tag Category named after the GCP Policy Taxonomy.
    • Creates a Data Tag for each GCP Policy Tag. (Hierarchy paths are prepended if the tag is below the root level).
    • Replicates GCP Policy Tag associations to corresponding Netskope DSPM classification fields.
    These categories and tags cannot be modified within Netskope DSPM. Update them directly in the GCP console; changes sync regularly to Netskope DSPM.

    Snowflake

    When connecting Snowflake Data Stores, you can auto-ingest Snowflake tags. This triggers the following actions:

    • Creates a Data Tag Category named after the Snowflake Data Store Identifier.
    • Creates a Data Tag for each Snowflake schema-level tag (prepended with the Data Store Identifier to prevent conflicts).
    • Replicates Snowflake tag associations to corresponding Netskope DSPM objects.

    In this Topic
    • Manage DSPM Data Tags