One login for the whole suite.
Sign in once with your own Tableau token and every tool is open to you, carrying the permissions Tableau already gives you.
How the platform worksBoreon’s TabTotal reads every warehouse, lakehouse and ontology you run. It answers on Claude, GPT or your own OpenAI-compatible endpoint, and every number comes from a metric you certified.
Built by certified Tableau Architects and Consultants, for the job we do ourselves.

Build with Agentic AI
Pick a published datasource and design through conversation. The AI drafts the spec; a deterministic emitter writes the workbook bytes.
A quarter of dashboard work, delivered the same day.
Ten minutes to a published dashboard in the project you chose. Hand it to a Tableau developer for final dressing and it is an afternoon, not a quarter.
Full data validation on every figure it can read. Each zone is re-queried live against your Tableau Cloud datasource and the check is shown, design value beside live value, and any zone that cannot be checked is named rather than quietly passed.
Every figure is read from your own governed datasource on your own session, and checked against live data before anything is published. What arrives is a real .twb tied to that datasource, ready to publish into the project you chose.
Where it sits
14 tools, one login, and an AI that runs on a key you own.
One login above every governed tool. One semantic contract beneath them, and an AI across everything.
Sign in once with your own Tableau token and every tool is open to you, carrying the permissions Tableau already gives you.
How the platform worksInherit Salesforce Data 360, Snowflake Horizon Catalog, Databricks Unity Catalog and the Palantir AIP Ontology into one governed business layer. The same entity in several platforms is one object, and where any two of them disagree, that becomes a finding.
Inside the semantic layerAsk about any workbook, datasource or lineage path and get an answer from your own governed model. Anything the Agent proposes arrives as a card your team approves, through the same gates you already trust.
How the AI worksThe Enterprise Semantic Layer
A read-only credential brings in your tables, columns, comments, tags, keys and grants.
Inside the semantic layerConnect a warehouse without giving up write access.
The connectors contain no write method at all, so a read-only credential is all TabTotal ever needs. Whatever your role cannot see, Boreon cannot see either.
Field-level lineage
How the answer gets there
Every AI Agent turn runs on a real model, on your own key. No surface hardcodes which one: it asks the running site which provider is live and renders that name.
Why Boreon’s TabTotal Orchestration Lake
Everything flows into one governed body, and only the layer on top can see across all of it. Salesforce Data 360, Snowflake, Databricks and Palantir AIP each verify themselves, and TabTotal reads them with your read-only credentials.
The identifiers that reach the SQL are the contract’s own copies, never text from the model or the caller. Nothing the model writes has a path to your warehouse, so the guarantee survives a model that gets things wrong.
Fields union by name, the description that exists wins, and the merged object remembers every warehouse it came from.
If the names in one question belong to different warehouses, nothing is sent anywhere, and the refusal names the candidates so you can ask again precisely.
Every pair of connected warehouses is compared, and each finding names its own pair: the object one of them holds and the other does not, or the object both hold with different field counts.
Each warehouse defines its metrics its own way, and those objects are excluded on purpose and never counted as drift. Warehouses that agree report nothing, however many you connect.
Divergence between warehouses joins the same findings total as every other governance job. The score you already read is where it lands.
The suite
Every tool answers deterministically on its own. AI is yours to switch on per run.
Prove what changed, who can reach it, and what it exposes.
Trace what feeds what, watch how it runs, and put the right view in front of the right people.
Describe what you want, or bring a file you already have, and get governed content back.
Evidence
In the formats your auditor asks for.
| Artefact | What it records | What it never records | Export |
|---|---|---|---|
| Admin audit | Every administrative change: who did what, to whom, and when. | No password, hash or authenticator secret, ever. | XLSX |
| Change ledger | Governed configuration changes in a SHA-256 hash chain, with before and after content hashes. | No secret values. Only their hashes. | CSV · JSON |
| AI log | Every AI call: surface, model, tokens, outcome. | Conversation content is not recorded by default. | JSONL · XLSX |
| Token log | PAT and embed-JWT events: minted, used, expired, refused. | Secret-free by construction, not by scrubbing. | XLSX |
Where it runs
The Enterprise license is one container on a Docker host you already run, behind the identity provider and the perimeter you already operate.
Every tool works fully without AI. Turn it on and it runs on your own provider key, or on your own OpenAI-compatible endpoint inside your network, so you decide where a prompt goes. If you would rather not host it yourself, we can run it for you, in the cloud of your choice.
Nothing changes until a person says so.
The AI reads, explains and proposes. Anything it suggests arrives as a card that routes into the same approval gate a person would use, with the same signature and dual-control rules. Publishing always creates a new copy and never overwrites your work.
One user, one month, on us. Point it at a real site with your own content.