What AI should never do to your Tableau server
The approve to run rule, in plain words. The assistant reads, explains and proposes, and a person owns the write path. What that costs, what it buys, and three questions to ask of any AI feature.
The model drafts, a person approves, and the approval is what runs. How a proposal reaches the gate, what the gate asks for, and what an approval has to record to be worth showing anybody.
Updated · 6 min read
Approve to run is a division of labour. The model reads what it is allowed to read, writes a proposal in words, and hands it to a person. That person opens it inside the tool that owns the action, sees what it would do, and signs. The signature is what runs. Take the person out of the middle and the proposal stays a paragraph on a screen.
The order matters more than it looks. In an agentic design the model acts and a person reviews later, if at all. Here the trigger belongs to the person. That makes the review the only route to the action, not a safety net somebody can be too busy to check.
A proposal waits for a person. Each one becomes a card the reader opens and approves in the tool’s own gate.
An assistant that acts and an assistant that advises are sold with the same words. They are different purchases. The difference shows up in the questions your risk function asks, and again on a bad day.
Both designs have their place. Inside a governed Tableau environment, the advisory one is what gets signed off. A single published data source can sit under a hundred workbooks, and one permission change reaches every one of them.
A proposal is only as bounded as the list it comes from. Each tool declares its own list of proposable actions on the server. The model picks from that list by name, and adds one block of action ids at the end of its answer.
That is the practical value of a list you can read end to end. A reviewer who wants every change this assistant could ever suggest reads one registry, in one file, in an afternoon. An instruction telling a model to behave itself leaves that reviewer with nothing to read.
An approval that records only that somebody clicked yes is a click. Five fields separate a gate from a dialog box.
The last field is the one people forget. A gate that quietly does the work again on a second submission turns a nervous double click into a second change. The audit then shows two approvals for one intended action.
Every registered action names the gate behind it. A proposal card can then tell the reader what they will be asked for before they open it. These are the registry’s own summaries.
Read the table as a whole and the pattern is the argument. Two signatures where content is published. A named approver where a migration runs. An acknowledgement where credentials are embedded. The weight of the gate follows the weight of the action, rather than sitting at one setting for everything.
One person on your own team can answer all four inside your own environment. No figure quoted in a data sheet tells you that much.
The approve to run rule, in plain words. The assistant reads, explains and proposes, and a person owns the write path. What that costs, what it buys, and three questions to ask of any AI feature.
An assertion is a sentence. Evidence is something a second person can check without asking you. What an audit trail has to contain, what a hash actually proves, and what to require of any tool that claims to produce one.
Four things get called governance: certification, ownership, stale content and change control. Here each one is written as a check you can run, not an aim you can state. It also covers the one change that passes a visual review and is still wrong.