You mentioned :
"I have tagged all of the events that represent changes to the system with tag="change"." And then :
"How on earth are all my auditd events getting tagged with "change" even though there is no event type that captures all of those events and tags them with "change"."
What's the config for the event type that you are tagging ? Are you sure that the event type isn't matching more than what you need ? Can you share the event type/tag config here ?
Also in your tag config, run a search for the "change" keyword and see if it's being applied to events that are not required.