Tags
When you need to perform actions on multiple assets, the Tagging feature makes management easier by allowing you to group assets based on assigned tags. This helps streamline bulk operations and improves visibility across your environment.
AIR supports tags in three complementary ways:
- Asset Tag Catalog — create and manage your organization’s tag vocabulary in Libraries, before or without assigning tags to assets.
- Manual tagging — assign or remove tags on selected assets from the Assets page.
- Auto (Asset) Tagging — automatically tag assets when rules match (for example after AIR Responder deployment). Auto Tagging can also be re-run at any time to reflect changes or updates. See the previous page for Auto Tagging rules.
Asset Tag Catalog
Section titled “Asset Tag Catalog”The Asset Tag Catalog is the organization-scoped library of tag names available in AIR. Use it to prepare taxonomy ahead of investigations, keep naming consistent, and manage tags without first attaching them to assets.
Open the catalog
Section titled “Open the catalog”- Go to Libraries in the main menu.
- Select Asset Tags.
The catalog lists tags for your selected / authorized organizations, including:
- Tag name
- Assigned Assets count
- Created date
Create a tag in the catalog
Section titled “Create a tag in the catalog”- Open Libraries → Asset Tags.
- Click Add New.
- Enter a tag name and select the organization (when more than one organization is available).
- Save.
The new tag appears in the catalog with Assigned Assets set to 0, and becomes available in the Assets sidebar and when assigning tags to assets.
Tag names must be unique within each organization. The same name can exist in different organizations.
Rename a tag
Section titled “Rename a tag”- In Libraries → Asset Tags, open the row actions menu (⋯) for the tag.
- Choose Edit Tag.
- Enter the new name and save.
Renaming updates the catalog entry and updates that tag name on assets that already use it (for the same organization). Filters and sidebar labels then use the new name.
Delete tags
Section titled “Delete tags”Deleting a catalog tag permanently removes it from the organization catalog and removes it from any assets that had it assigned. The assets themselves are not deleted.
Single delete
- Open the row actions menu (⋯) for the tag.
- Choose Delete and confirm.
Bulk delete
- Select one or more tags with the checkboxes.
- In the bulk action bar, choose Delete and confirm.
Jump to assets that have a tag
Section titled “Jump to assets that have a tag”In the catalog, click the Assigned Assets count for a tag. AIR opens the Assets view with that tag filter applied, so you can review matching assets and run acquisition, triage, or other tasks on the filtered set.
Create and manage tags from the Assets sidebar
Section titled “Create and manage tags from the Assets sidebar”On the Assets page, the left-hand Tags tree shows the catalog for the current organization context.
Create a tag from the sidebar
Section titled “Create a tag from the sidebar”- Go to Assets.
- In the Tags section header, open the actions menu (⋯).
- Choose New Tag, enter a name, and save.
The tag is added to the catalog and appears in the sidebar immediately—even if no assets are assigned yet.
Filter assets by tag
Section titled “Filter assets by tag”- Expand the Tags section in the Assets sidebar.
- Select a tag to filter the asset list to assets that have that tag.
You can then apply acquisition, triage, or other tasks to the filtered assets.
Assign tags to assets (manual tagging)
Section titled “Assign tags to assets (manual tagging)”To create Tags for your assets—or assign existing catalog tags:
-
Navigate to Assets in the Main Menu and select the assets to which you want to assign tags.
-
Open the add/remove tags dialogue. Search the drop-down list for an existing Tag, or type a new Tag name and click Add this as a new tag.

Tags: Adding a new Tag (for example
rm2) -
From the same dialogue box, you can remove Tags from the selection by selecting the cross.
-
After tags are assigned, filter your assets by tag (sidebar or filters) to view specific groups and apply relevant acquisition or triage tasks just to them.
Typing a new name during assignment also adds that tag to the organization’s Asset Tag Catalog.
Auto Tagging and the catalog
Section titled “Auto Tagging and the catalog”When you create or update an Auto Asset Tag rule, AIR also ensures the rule’s tag exists in the Asset Tag Catalog for the organizations covered by that rule:
- If the rule targets specific organizations, the catalog tag is created for those organizations.
- If the rule applies to all organizations, the catalog tag is created for every organization.
That means rule-defined tags show up in Libraries → Asset Tags and the Assets sidebar as soon as the rule is saved—without waiting for the first matching asset.
For how Auto Tagging rules work and when they run, see the Auto Tagging page in this section.
Quick reference
Section titled “Quick reference”| Goal | Where |
|---|---|
| Pre-create or manage tag names | Libraries → Asset Tags |
| Create a tag without leaving Assets | Assets sidebar → Tags → ⋯ → New Tag |
| Rename a tag | Catalog row ⋯ → Edit Tag, or Assets sidebar tag ⋯ → Edit Tag |
| See assets that have a tag | Catalog Assigned Assets count, or select the tag in the Assets sidebar |
| Assign / remove tags on assets | Assets page → select assets → add/remove tags dialogue |
| Auto-apply tags by rule | Auto Tagging (previous page); rule save also creates the catalog entry |