Skip to content

The words this work runs on. Defined plainly.

Tableau governance and semantic layers, in a sentence or two each. Where two terms only make sense together, each one points at the other.

The definitions

A

Approve to run
The rule that anything which would change something reaches a named person first. Software may read, explain and draft. A person approves, and that approval is what runs the work.

See also Audit trail · Governance

Audit trail
The record of who approved what, and when. In TabTotal, every governed decision is written into a hash chain. An auditor can re-check the sequence from the export instead of taking the report on trust.

See also Approve to run · Hash chain · Content hash

C

Calculated field
A field set by an expression rather than read from a column. It is written inside a workbook or a data source. This is where one business metric quietly picks up a second meaning. The expression lives with the workbook, not with the warehouse.

See also Field · Measure · Semantic Layer

Catalogue
The place a platform records what its data is: tables, columns, comments, tags, keys and grants. TabTotal reads three of them: Salesforce Data 360, Snowflake Horizon Catalog and Databricks Unity Catalog. A catalogue is work your team has already done. A governance tool should inherit it, not ask for it again.

See also Salesforce Data 360 · Unity Catalog · Horizon Catalog · Semantic Layer

Certification
A mark an admin puts on a data source or workbook. It says: this is the version to use. It speaks to trust, not correctness. It goes stale the moment the thing it marks changes and nobody re-checks it.

See also Published data source · Stale content · Governance

Column-level lineage
Lineage recorded at the grain of a single column, not a whole table. It answers the question a table-level map cannot. Change one column, and it names every field, worksheet and dashboard that is hit. It names the safe ones too.

See also Lineage · Field · Grain

Connected App
A trust relationship registered in Tableau. It lets a service mint a signed token for a user without holding that user’s password. It is the service credential, where a personal access token is the person credential.

See also Personal access token · JSON Web Token

Content hash
A fingerprint of an object’s content. It is kept so a later version can be compared with an earlier one. It turns "this changed" from a memory into a fact.

See also Hash chain · Drift · Audit trail

Cortex Analyst
Snowflake’s natural-language question surface. It answers from a semantic view: the definitions your team published, not ones guessed from column names.

See also Semantic view · Horizon Catalog

Custom view
A saved set of filters and selections on top of someone else’s dashboard. The person who saved it owns it. Custom views belong to individuals and stay hidden in most inventories. They are the thing most often lost when a person leaves.

See also Workbook · Subscription

D

Data contract
An agreement about what a dataset guarantees. It covers the fields, their types, their meaning, and the rules a value must meet. A contract is worth having only if something checks it. That is the difference between a published definition and an enforced one.

See also Semantic Layer · Measure · Governance

Data source
The Tableau object that connects to data and shapes it for analysis. It holds the connection, the joins, the field names, and any calculations built on them. It can live inside one workbook, or be published for everyone.

See also Published data source · Extract · Live connection

Data steward
The person who looks after a field or dataset day to day. That covers its description, its quality rules and its classification. The owner is a separate role and carries the accountability. The difference matters when something needs fixing fast.

See also Governance · Field

Dimension
A way of slicing a measure: region, product line, month, channel. In a semantic layer, a dimension is a named, published object. It is not whichever column someone dragged onto the shelf.

See also Measure · Entity · Semantic Layer

Drift
The gap that opens between two things that were once the same. Perhaps a warehouse and the layer describing it. Perhaps two warehouses holding the same logical table. Drift is normal. Missing it is the problem.

See also Content hash · Semantic Layer · Governance

E

Entity
The business object a semantic layer describes: customer, order, policy, claim. Dimensions and measures are defined against an entity. That is why the same dimension name can sit on two entities at different grain.

See also Dimension · Measure · Grain

Extract
A compressed snapshot of data that Tableau stores and queries itself, refreshed on a schedule. Extracts are fast and self-contained. Each one is also a copy of your data with an age.

See also Live connection · Data source

F

Field
A named thing you can put on a shelf or ask a question about. In an inventory, a field is a name and a type. A governed layer holds far more. It carries the physical source, the constraints, the quality rules, the business description, the owner, the steward and the classification.

See also Calculated field · Column-level lineage · Semantic Layer

G

Genie
Databricks’ natural-language question surface. It answers from a metric view. The measures it computes are the ones your team defined in Unity Catalog.

See also Metric view · Unity Catalog

Governance
Knowing what you have, who answers for it, and what has to be true before it changes. It is often read as a set of restrictions. In practice, most of it is inventory, ownership and a record of decisions.

See also Approve to run · Audit trail · Data steward

Grain
The level of detail one row stands for: one order, one order line, one customer per day. Two measures that look alike but disagree are often read at different grain. Both can be right.

See also Measure · Entity

H

Hash chain
A run of records where each entry carries a fingerprint of the one before it. Change an old entry and every entry after it breaks. Anyone holding the export can check the record for tampering.

See also Audit trail · Content hash

Horizon Catalog
Snowflake’s governance catalogue: object metadata, tags, keys and access policy in one place. Its define-once object is the semantic view. Tag lineage flows from database down to table, unless something more specific overrides it.

See also Semantic view · Cortex Analyst · Catalogue

J

JSON Web Token
A short-lived signed token carrying a set of claims. The receiver checks it against the signer’s key. Tableau Connected Apps issue one so a service can sign in. An embedding token is spent the moment it is used.

See also Connected App · Personal access token

L

Lineage
The map of what a piece of content depends on, and what depends on it. Read one way, it answers "where did this number come from". Read the other way, it answers "what breaks if I change this".

See also Column-level lineage · Field · Drift

Live connection
A connection that queries the source system each time someone opens the view, never from a stored snapshot. The numbers are current, and every view is load on the warehouse.

See also Extract · Data source

M

Measure
A number, plus the exact expression that produces it: its aggregation, its filters and its grain. A field named Net Revenue is not a measure. A definition of Net Revenue that everything computes from is.

See also Dimension · Grain · Semantic Layer

Metric view
Databricks’ define-once object, catalogued in Unity Catalog. It holds entities, dimensions and measures as a governed object the platform itself understands, so Genie answers from your definitions.

See also Unity Catalog · Genie · Semantic Layer

P

Permission rule
The grant or denial that decides who may see or do what. It is set on a project, workbook or data source. Tableau already holds these. A governance tool inherits them and keeps no second opinion about who may see what.

See also Project · Row-level security · Site

Personal access token
A named, revocable credential a Tableau user creates for themselves. Tools acting as that person use it in place of a password. It carries exactly that user’s permissions. A tool holding one can never see more than the person it belongs to.

See also Connected App · Read-only credential

Personally identifiable information
Data that identifies a person, on its own or joined with something else. Whether a field counts is a call someone has to make and record. A scanner cannot settle it alone.

See also Governance · Data steward · Row-level security

Prep flow
A Tableau Prep pipeline that cleans, joins and reshapes data, then writes the result somewhere. Flows are content like anything else. They have an owner and a schedule. They break when the thing upstream of them moves.

See also Lineage · Data source · Site

Project
The folder a Tableau site sorts content into. Most permission rules are set at this level. Nested projects can lock their permissions. "Who can see this" is often a project question, not a workbook question.

See also Permission rule · Site · Workbook

Published data source
A data source published to the site so many workbooks can share it. It has one owner and one definition of its fields. That makes it the most useful governance object Tableau has. A shared definition is the only kind that can be certified.

See also Data source · Certification · Workbook

R

Read-only credential
A warehouse login granted only the right to read. It is the boundary of what a governance tool can reach. You set it in your own warehouse, and you can revoke it there without asking anybody.

See also Personal access token · Catalogue

Row-level security
A rule that limits which rows a given person sees. One dashboard can then serve many audiences safely. It lives with the data, not with the view. It holds however the data is reached.

See also Permission rule · Personally identifiable information

S

Salesforce Data 360
Salesforce’s data platform and its catalogue of data model objects. Its define-once object is the semantic model. The question surface that model feeds is Tableau Semantics.

See also Semantic model · Tableau Semantics · Catalogue

SAML
The standard an identity provider uses to vouch for a person. It sends an application a signed assertion: this person is who they say they are. It is how a firm signs in to outside software with its own directory.

See also Time-based one-time password · Site

Semantic Layer
A governed description of your data, sitting between the physical tables and the people asking questions. It holds entities, dimensions and measures, and it stores meaning, not rows. A metric is defined here once, and everything that computes it computes it the same way.

See also Measure · Dimension · Entity · Data contract

Semantic model
Salesforce Data 360’s define-once object, registered in its catalogue. Same shape as a metric view or a semantic view. It names entities, dimensions and measures, and the platform’s own tools respect them.

See also Salesforce Data 360 · Tableau Semantics · Semantic Layer

Semantic view
Snowflake’s define-once object, catalogued in Horizon Catalog. Its dimensions carry their entity name. The same dimension name is often defined on two entities at different grain. A bare name would be unclear.

See also Horizon Catalog · Cortex Analyst · Grain

Site
A tenant on Tableau Server or Tableau Cloud, with its own users, projects, content and permissions. A person can belong to several, and content never crosses between them. That is why "which site" is the first question in almost every governance conversation.

See also Project · Tableau Cloud · Tableau Server

Stale content
Content no one has opened for long enough to put its use in doubt. A dashboard no one views. An extract no one refreshes. A subscription landing in a mailbox no one reads. Age alone is not a verdict. Removing it is a decision somebody makes.

See also Certification · Subscription · Governance

Subscription
A scheduled delivery of a view to someone’s inbox. Subscriptions outlive the interest that created them, and they survive the person who set them up. They are one of the clearest signals of content no one uses.

See also Stale content · Custom view

T

Tableau Cloud
The version of Tableau that Salesforce hosts and runs. Sites are provisioned, not installed, and there is no server for your team to patch.

See also Tableau Server · Site

Tableau Semantics
The question surface that reads a semantic model registered in Salesforce Data 360. It is why a definition published there travels beyond where it was written.

See also Semantic model · Salesforce Data 360

Tableau Server
The version of Tableau a firm installs and runs itself. It runs on its own machines, on its own schedule. Its content model closely matches Tableau Cloud, so a move between them is possible, and the differences are worth listing with care.

See also Tableau Cloud · Site

Time-based one-time password
The six-digit code an authenticator tool builds from a shared secret and the clock. It is the second factor at sign-in. A stolen password on its own will not get in.

See also SAML · Governance

U

Unity Catalog
Databricks’ governance catalogue: tables, columns, comments, tags, keys and grants in one namespace. Its define-once object is the metric view. Genie reads it when it answers a question.

See also Metric view · Genie · Catalogue

W

Workbook
The Tableau document holding worksheets, dashboards and, often, its own data sources and calculations. A workbook is the unit people share. That is also why a definition written inside one tends to stay inside it.

See also Published data source · Calculated field · Custom view