Skip to main content
Category: Classification and Taxonomy

Tagging

Also known as: Data tagging
Simply put

Tagging is the practice of attaching descriptive labels to a piece of information or content, such as a document, image, or dataset, so it can be identified and found more easily. These labels typically take the form of metadata that describe what the item is or how it should be handled. In a recordkeeping context, tagging supports organizing and retrieving materials, though the labels alone do not by themselves make an item an authoritative record.

Formal definition

Tagging is the process of assigning descriptive labels, usually captured as metadata, to information objects such as documents, images, videos, or datasets to support their identification, classification, and retrieval. The tags may describe content, context, or handling requirements and can inform downstream processes such as classification and, potentially, retention or disposition decisions, depending on organizational policy and system configuration. Tagging should be distinguished from formal records classification against a controlled scheme or file plan: while tagging can supplement or feed such classification, applying tags does not in itself establish the authenticity, reliability, integrity, or usability properties that characterize an authoritative record. The evidence available describes tagging in general information-management and data-security terms rather than as a defined recordkeeping term, so its precise application in a records program will vary by system, standard, and jurisdiction.

Why it matters

Tagging matters because the ability to find, identify, and appropriately handle information depends heavily on the descriptive labels attached to it. In large repositories where documents, images, videos, and datasets accumulate rapidly, well-applied tags support retrieval and can help route content into downstream processes such as classification and, depending on organizational policy and system configuration, retention or disposition decisions. Without consistent labelling, valuable material may become effectively unfindable even when it has been retained.

At the same time, tagging carries a risk that professionals in this field should keep in view: the presence of tags can create a false impression of control. Applying descriptive labels does not, on its own, establish the authenticity, reliability, integrity, or usability properties that distinguish an authoritative record from mere information or a copy. An item can be richly tagged and still fall short of the requirements of a formal recordkeeping program. Tagging is best understood as a supplement to, rather than a substitute for, records classification against a controlled scheme or file plan.

The evidence available describes tagging in general information-management and data-security terms rather than as a defined recordkeeping practice. Its precise value and application in any given records program will therefore vary by system, applicable standard, and jurisdiction, and organizations should be cautious about treating tagging conventions from one context as transferable to another without validation.

Who it's relevant to

Records managers
Records managers encounter tagging as a mechanism that can support organizing and retrieving materials, but should be careful to distinguish it from formal classification against a controlled scheme or file plan. Understanding where tags feed classification, and where they do not establish the properties of an authoritative record, helps them set appropriate expectations for what tagging can and cannot deliver in a records program.
Information governance officers
For those responsible for the broader accountability framework spanning policy, risk, and value, tagging is one input among many that can influence how information is identified and handled. Governance officers may need to define policy on how tags are applied and how, if at all, they inform retention or disposition decisions, recognizing that this varies by system configuration and organizational policy.
Information security and data protection professionals
Because tagging is often described in data-security terms, security and privacy practitioners may use tags to label information according to handling requirements. They should note that such labels support identification and routing but do not, by themselves, guarantee the integrity or authoritative status of the underlying content, and that obligations tied to handling categories typically depend on jurisdiction and sector.
System administrators and content managers
Those configuring and maintaining repositories are responsible for how tags are captured, whether manually or through automated tools, and how they connect to downstream processes. Their configuration choices determine much of the practical value tagging delivers, including whether tags can meaningfully feed classification, retrieval, or handling decisions.

Inside Tagging

Metadata assignment
Tagging involves attaching descriptive, structural, or administrative metadata to a record or item, typically through terms, labels, or attributes that support later retrieval, classification, and management. The nature and extent of metadata applied often depend on organizational policy and the recordkeeping system in use.
Controlled vocabulary or free-text terms
Tags may be drawn from a controlled vocabulary, taxonomy, or thesaurus to promote consistency, or applied as free-text keywords. Controlled approaches generally improve reliability and interoperability, while free-text tagging can introduce variation that complicates retrieval.
Classification linkage
In a recordkeeping context, tagging can support or connect to classification schemes and file plans, but tagging is not itself equivalent to classification. Classification typically establishes the business context and aggregation of records, whereas tags often add supplementary access points.
Retention and disposition signals
Tags may carry or reference information relevant to retention, disposition, security, or access control, such as sensitivity markings or retention category identifiers. Whether such tags reliably drive disposition actions depends on how the system is configured and governed.
Manual and automated application
Tagging may be performed by users, by records staff, or through automated or assisted means. The method chosen affects consistency, completeness, and the auditability of how metadata came to be applied.

Common questions

Answers to the questions practitioners most commonly ask about Tagging.

Is tagging the same as classification in records management?
No, though the two are often conflated. Classification typically involves assigning records to a controlled scheme or business classification structure that reflects functions and activities, often forming the basis for retention and disposition decisions. Tagging generally refers to attaching descriptive labels or keywords to records or information, and these tags may be applied more flexibly, sometimes by users and sometimes without a controlled vocabulary. Tagging can support classification, but it does not by itself establish the authoritative structure that classification provides. Depending on organizational policy, tags may be informal aids to retrieval rather than governed metadata, so they should not be assumed to carry the same authority as a formal classification scheme.
Does applying tags to content turn that content into a record or guarantee its retention?
Not on its own. Tagging is a means of describing or labeling information to aid retrieval, organization, or processing, but it does not confer the properties that make something a record, such as authenticity, reliability, integrity, and usability. Whether an item is treated as an authoritative record, a copy, a draft, or transitory information depends on its role as evidence of activity and on organizational policy, not on the presence of a tag. Similarly, tags do not by themselves trigger retention or disposition outcomes unless they are deliberately linked to retention rules within a governed system. Retention typically depends on classification and applicable requirements rather than on descriptive tags alone.
Should tagging be performed manually by users or automatically by the system?
Both approaches are used, and the choice often depends on volume, risk, and the maturity of the recordkeeping environment. Manual tagging by users can capture contextual knowledge but tends to be inconsistent and may vary in coverage across an organization. Automated or system-assisted tagging can improve consistency at scale but may require validation, since inferred tags can be inaccurate. In many organizations a hybrid model is adopted, where automation proposes tags and users or governance controls confirm or correct them. The appropriate balance depends on organizational policy and on how far tags are relied upon for downstream decisions.
How can a controlled vocabulary improve the reliability of tagging?
A controlled vocabulary constrains the terms available for tagging, which typically reduces duplication, synonyms, and inconsistent spelling that can undermine retrieval. Without such control, free-text tags may proliferate and become difficult to maintain over time. Using an agreed set of terms, and defining their meaning, generally improves consistency across users and systems and makes tags more dependable for search, reporting, and governance. The design of a controlled vocabulary usually depends on organizational needs, and it may require ongoing maintenance as terminology and business activities change.
What governance considerations apply when tags are used to support retention or disposition?
Where tags are relied upon to inform retention or disposition, they generally need to be governed with the same care as other metadata that drives such decisions. This often includes defining who may apply or change tags, ensuring the integrity of tags is maintained over time, and confirming that tag values map reliably to retention rules or classification. Because disposition may include transfer or permanent preservation as well as destruction, organizations typically need assurance that a tag-driven action reflects the correct outcome. The specific controls depend on organizational policy and, in some cases, on applicable requirements that vary by jurisdiction and sector.
How should inconsistent or legacy tags be handled during system migration or clean-up?
Inconsistent or legacy tags are common where tagging has been applied over time without controls, and they often need review before they can be trusted. Practical steps may include analyzing existing tags to identify duplicates and ambiguous terms, mapping them to a controlled vocabulary where one exists, and deciding which tags to retain, consolidate, or retire. It is generally advisable to preserve the integrity and context of records during any remediation, so that changes to tags do not compromise the ability to rely on the underlying records as evidence. The scope and rigor of such clean-up typically depend on how far the tags influence retrieval, retention, or other governed processes.

Common misconceptions

Tagging is the same as classifying a record.
Tagging and classification are related but distinct. Classification generally situates a record within a business context and an aggregation structure, supporting its meaning as evidence, while tagging often adds supplementary access points or descriptive labels. Tags may complement classification but do not typically substitute for it.
Applying tags is enough to make something an authoritative record.
Metadata such as tags can support the usability and management of a record, but the properties that make something a record, such as authenticity, reliability, integrity, and usability, depend on more than added labels. Transitory information or an uncontrolled copy does not become an authoritative record simply because it has been tagged.
Tags automatically enforce retention and disposition.
A tag may reference retention or sensitivity information, but whether it actually drives a disposition action depends on system configuration and governance. Depending on organizational policy and the tools in use, tags may be purely descriptive and require separate controls to have any operational effect on disposition.

Best practices

Where consistency and retrieval matter, draw tags from a controlled vocabulary, taxonomy, or thesaurus rather than relying solely on free-text terms.
Keep tagging aligned with, but not a replacement for, the classification scheme and file plan, so that the business context and aggregation of records remain clear.
Define and document which tags carry operational meaning, such as sensitivity or retention markings, and verify how the recordkeeping system acts on them before treating them as controls.
Establish clear responsibility for who applies tags and when, distinguishing manual, assisted, and automated methods, and consider the auditability of how metadata was assigned.
Do not rely on tagging alone to establish that an item is an authoritative record; ensure the underlying properties of authenticity, reliability, integrity, and usability are addressed through appropriate controls.
Periodically review and reconcile tags against organizational policy and any applicable jurisdictional or sector requirements, using qualified judgement since obligations depend on jurisdiction and context.