Everything flows in, read-only
Five platforms, each connected with a credential you issue. TabTotal inherits their catalogues rather than copying your data out of them.
Boreon’s TabTotal Orchestration Lake
The Agent rides all 14 tools, plus Home and the admin console. It answers questions and drafts changes, and anything that would actually change something reaches a person first, in the gate your team already trusts.
Your data is the only thing the AI can reach.
The AI works inside a database engine started with external access switched off. It reads the data you gave it and nothing else on the machine. The boundary is the engine itself, not a list of words to watch for. How a question is phrased makes no difference to it.
AI Orchestration
Tableau, Salesforce Data 360, Snowflake, Databricks and the Palantir AIP Ontology arrive read-only and stop being five separate systems. The AI works across the whole surface, not one corner of it.
The same entity arriving from more than one platform becomes one object, and where two of them disagree that becomes a finding rather than two rows nobody reconciles. That is what makes an answer possible at all: there is one thing to ask about.
Five platforms, each connected with a credential you issue. TabTotal inherits their catalogues rather than copying your data out of them.
Layers, tables, columns, keys, tags and owners arrive as your own names. The layer imposes no taxonomy of its own.
One Agent rides every one of the fourteen tools, and ten read tools reach the same governed body from your own MCP client.
Every answer is computed from a metric you certified. Anything that would change something stops at a person first.
The same Agent picks up the context of whichever surface you are on.
It sees the surface you are on and the governed model behind it. A question about this workbook means this one.
It answers in plain language about what is actually there, and names where the answer came from.
When something should change, it drafts the change and hands it to the approval gate your team already uses.
When a question needs the data itself, it runs real SQL against your own copy.
The objects, fields and certified definitions you approved. An answer starts here, in the vocabulary your business agreed on.
The Agent runs real SQL against a per-user copy of your data. No sample, and no guess about what a sample implies.
Every tool completes on its own engine, and AI is a tick box per run.
Nothing leaves for a model unless somebody chose to send it. The answer you get today is the answer you get tomorrow, which is what you want before you sign a governance report.
| Aspect | Answer |
|---|---|
| Whose key | Yours. Boreon supplies none, and there is no shared pool. |
| Which provider | Anthropic or OpenAI, including Azure OpenAI deployments. |
| Your own endpoint | Any OpenAI-compatible endpoint, including a proxy inside your own network. |
| Scope | One key per user, or one key for the whole site. |
| At rest | Encrypted. |
| After you save it | It is shown to nobody again, and it stays out of every log. |
The OpenAI client takes a base URL. Anything speaking the OpenAI API can serve it: a gateway your platform team already runs, or a model on your own hardware. Set that address and a prompt travels to a machine you operate. It never leaves your building, even with AI switched on.
Verified against the shipping product on 14 August 2026. Azure OpenAI uses the same field for your resource endpoint.
The Agent drafts. Your team decides, and that order holds on every surface.
A proposal arrives as an approve-to-run card, and the card goes into the same gate the owning tool already has, with the same signature and dual-control rules your governance team wrote. Nobody has to learn a second approval process for the AI.
Nothing changes until a person says so.
The AI reads, explains and proposes. Anything it suggests arrives as a card that routes into the same approval gate a person would use, with the same signature and dual-control rules. Publishing always creates a new copy and never overwrites your work.
It ships switched off.
It offers 10 read-only tools, and it authenticates with your own Tableau token. The endpoint sees exactly what you see, because it is you, using the permissions you already have. It ships switched off, and an administrator turns it on when your organisation is ready for it.
Calls, tokens, models and estimated cost, reported per person in the admin console.
How many times each person used it.
What each call consumed, in and out.
Which model answered.
Labelled an estimate, because that is what it is.
Every figure in the design comes from a live query on your own session.
Publishing takes an approval plus a re-typed signature, and it always creates a new workbook. The thing you already have is still there in the morning. You get the speed of describing what you want, with the paperwork already done.
Every figure on a designed dashboard is real.
Before each design turn, TabTotal queries your own session for a live data profile, and every quantity comes from it. If your connection cannot answer, the preview is labelled as placeholders and says why.
Your key, your gates, and a month to see whether the drafts are any good.