---
title: "Tag Compliance"
canonical: "https://ai-docs.certero.com/space/CXCM/108299442/Tag%20Compliance"
format: markdown
---
Tag Compliance policies will track the adherence of custom sets of resources to custom tag key criteria.

Policies have a start date, and a set of filters to define the resources scope.

There are three types of policy:

![image-20250912-065242.png](media://905cb918-54b8-4443-b8d3-8a08ed89d361)

**Required tag** checks that resources in scope have a specific tag key assigned.

**Prohibited tag** checks that resources in scope **do not** have a specific tag key assigned.

**Tags correlation** checks that resources with one key must also have a second.

The policy example below checks that load balancers in the Azure Dev pool have an **owner **tag key assigned:

![image-20250912-062515.png](media://0bd07a65-3870-4852-b7da-6cef78c4233b)

Users will receive [Email Notifications](https://certero.atlassian.net/wiki/spaces/CXCM/pages/108298614) of tag policy breaches, and breaches will be called out on the **Policy Violations **tile of the **Executive Dashboard**.

The main **Tag Compliance** screen shows a list of existing policies and their compliance status.

Clicking on a policy opens the policy details screen, where you can inspect the violation history for the policy and switch to the [Resources](https://certero.atlassian.net/wiki/spaces/CXCM/pages/108298896) screen, pre-filtered to show the non-compliant resources:

![image-20250912-070228.png](media://7c434660-3b04-4f89-a126-ff2af213d168)

> ℹ️ Note that once a policy is configured, you can’t edit the criteria or filters, as this would break the validity of the violation history.