Create and apply markings
Use the Markings screen to manage the global catalog of labels that restrict access to sensitive resources. After you create a marking, grant access and apply it to a resource. Only users who hold that grant can access the resource.
Only users with the Administrator type can access this screen. A user without permission who opens the address directly is redirected to Home.
How markings work
- An administrator creates a marking.
- On the marking edit screen, the administrator grants access to users and groups.
- An owner or administrator applies the marking from the resource details.
Only users with an access grant can open a marked resource. Resource owners and administrators are also blocked if they do not hold a grant.
Open Markings
Select System → Settings → Markings in the sidebar.

Markings list
Registered markings appear in a table with Name and Tags columns. The description appears below the name.
- Search: Narrow the list by entering a name or description in the search field.
- Bulk delete: Select multiple rows with their checkboxes, then select Delete.
- Open edit screen: Select a row.
Create a marking
-
Select Create at the top right of the list. The Create marking screen opens.
-
Enter the fields.
Field Required Description Name Required Identifier for the marking, for example confidential.Alias Optional When present, displayed instead of the name in lists and badges. Description Optional Records the meaning of the marking and who should receive access. Tags Optional Enter a tag and press Enter to add it. -
Select Create. The edit screen opens immediately so you can manage access grants.
Grant access
Under Access grants on the edit screen, manage who can access resources restricted by this marking.
- Enter at least two characters of a user or group name in the search field.
- Select the target and select Grant.
To revoke access, select Remove access grant in the holder's row.
Removal applies without a confirmation dialog. The user immediately loses access to resources restricted by the marking.
Apply a marking to a resource
Apply a marking from the resource details in a collection. The Manage markings button appears on dataset, code, pipeline, agent, and knowledge details.
- Select Manage markings in the resource details.
- In the Manage markings dialog, select or clear the required marking.
- Changes are saved immediately.
- Resource owners and administrators can apply a marking.
- Only administrators can remove a marking.
- A shield badge appears beside the title of a marked resource.
Capture: Manage markings dialog on a resource detail screen, including the marking checklist and the badge beside the detail title.
When access is blocked
Opening a restricted resource without a grant displays, “This resource is restricted by a marking and cannot be accessed.” Ask an administrator for an access grant to the marking.
Delete a marking
Select Delete from the row action menu or bulk action bar, then select Delete in the confirmation dialog.
Deleting a marking removes its restriction from every resource. Before deletion, confirm that no resource still requires this protection.
Next steps
- Policies overview — Markings block access at the resource level; policies control data at the column and row level.
- Create and manage groups — Grant access to groups instead of individuals to simplify administration.