Skip to content

Govern a Tableau Cloud site with a read-only token

You sign in with your own personal access token. It stays on the server, for that session only. Your browser never holds it. TabTotal sees what your Tableau role sees, and no more.

Your token is the boundary

The token you sign in with is the one every tool uses. It is the only credential in play, and no service account sits behind it. The product reaches what you can reach, and no further.

  • Kept on the server, for the session, never on disk
  • The browser never sees it at any point
  • A connected-tool JWT covers the few places a token cannot reach

Discovery reads, it does not write

The inventory, the lineage and the usage all come from reading the site. Discovery changes nothing as it goes. Connect a live site, look at what comes back, and decide later.

  • Content, owners, permissions and usage, read from the site
  • Field level lineage where the catalogue can answer it
  • Every finding names what produced it

Every change is a plan you approve

When a tool does change something, it stages the change first. A person approves it. That approval is the event on the record.

  • The staged plan lists every item the change would touch
  • Approve it, narrow the scope, or leave it alone. Nothing is applied without that approval
  • Where the AI drafts the change, you are still the one who applies it

What it reads

Content and owners

Workbooks, data sources, flows, subscriptions and the people who own them.

Usage

Read from the site, never estimated. A call on stale content has evidence behind it.

Permissions

The permission that applies in practice.

The tools that do the most here

Every tool works on every connection. These are the ones this system gives the most to.

  • Portal

    Explore Tableau using AI

    Version 0.25.2

  • Lineage

    Trace Your Data Lineage

    Version 3.23.3

  • Quality

    Analyze Workbook Quality

    Version 3.10.0

  • Guard

    Run a Cybersecurity Scan

    Version 3.4.3