QuestionQ93
Implement Data Protection and RecoveryA Data Engineer must create a tag-based masking policy that determines whether data is masked according to the label-string value assigned to the salary column in the staff table. The Engineer created the tag and masking policy using these commands:
USE SCHEMA governance.tags;
CREATE TAG hr_col_salary;
USE ROLE masking_admin;
USE SCHEMA governance.masking_policies;
CREATE MASKING POLICY salary_mask_tag_policy
AS (val number) RETURNS number ->
CASE -
WHEN SYSTEM$GET_TAG_ON_CURRENT_COLUMN('tags.hr_col_salary') = 'visible' or 'payroll_admin' = current_role() THEN val
ELSE -1 -
END;
ALTER TAG hr_col_salary SET -
MASKING POLICY salary_mask_tag_policy;
How should the Engineer apply the tag to ensure that only users with the payroll_admin role can access the data?
Community Discussion