Certifying a data source, and keeping the claim true
A certification is a flag and a sentence, set by somebody who was sure at the time. What that asserts, what it leaves to you, who should hold it, and the three ways it quietly stops being true.
Read a published data source back from a Tableau site and the certification arrives as just two fields: a flag saying it is certified, and a free-text note.
The badge asserts exactly this much. A person who held the permission to do it set the flag, on some date, and wrote whatever they chose in the note. Everything a reader takes from it beyond that is inference, and the inference is the part that goes wrong.
The note is therefore the only place the actual claim can live, and it is optional. A certification with an empty note is a badge whose meaning is held in one person’s memory, which is a fine place for it right up until that person is on holiday.
What the badge leaves to you
Four separate questions a certified data source leaves open, each of which somebody eventually assumes it has answered.
Whether the numbers are right
The flag records a judgement about fitness for use. The arithmetic is a separate question, and the way to answer it is to compare what the data source serves now against what it served before.
Whether the data is current
Certification and refresh move independently. A data source whose extract stopped updating last quarter carries its badge exactly as it did on the day it was set.
Who is allowed to open it
Certification changes how prominently the data source is offered when somebody goes looking for one. Permission is decided by its own rules, and setting the flag leaves those rules where they were.
What happens downstream
A workbook built on a certified data source can still define a measure locally. The badge travels with the data source. The definition travels with whoever last edited the workbook.
The fourth is the one that produces two numbers with the same name in the same meeting, both of them defensible, neither of them wrong in a way anybody can point at.
Who should hold the certification
The certifier should be whoever can answer the next question about it. That is usually the steward for the subject area, sometimes the analytics engineer who built the model, and only rarely the administrator who happens to have the permission to click it.
Ownership on a Tableau site is a per-item field, and six kinds of object carry one: workbooks, published data sources, flows, projects, subscriptions and refresh tasks. The owner and the certifier can therefore be two different people, and usually should be. The owner keeps it running. The certifier vouches for what it means.
Put both names in the note, with a date, even though the note is free text and nothing enforces the shape. Free text is what the platform hands you. Use it as a record, not a slogan.
Certifying is an act a person performs, and it is worth treating that as a rule. In this suite a finding can be raised by a deterministic detector or by an AI pass, and moving it to confirmed requires either a deterministic match or a human signature. Software gathers what a certifier needs. Signing stays with the person whose name goes on it.
The three ways a certification stops being true
Ordered by how quietly each one happens.
The certifier moves on. The flag persists and the judgement behind it now has no author. Nothing on the screen changes, which is what makes this the common one.
The model changes underneath. A field is renamed, a calculation is replaced, a join is widened. The badge was set against a definition that has since been edited away.
The refresh stops. The definition is still right and the numbers are old, and the badge vouches happily for both.
The middle one deserves the most attention because it is the hardest to see. Two saved versions of the same content differ in thousands of ways that carry no meaning at all, because the file is rewritten on every save: identifiers regenerate, attributes reorder, whitespace churns. The comparison that works matches fields by their internal name, which survives caption renames and reordering, and reports only the differences that mean something.
One of those differences is always a failure and never a warning: a calculated field is removed and a direct database field with a similar caption takes its place. Every label still reads the same. The number is now something else. The badge is still on.
Revision history is the cheapest route back to the previous definition, and it is switched off on plenty of sites. An empty revision list is an honest answer, not an error, and it is also the answer telling you the previous definition has gone.
Putting something computed beside the badge
A flag is a claim, and the useful thing to set next to a claim is a measurement. Where the two agree, the certification is doing its job. Where they disagree, you have found the conversation worth having this quarter.
One worked example of what a measurement can look like. A semantic layer profile scores itself on five dimensions, each a percentage over the fields the model holds real evidence for: how many are documented, how many carry a quality rule, how many carry a classification decision, how many have a named steward, and how many objects sit clean against the naming contract.
The headline is the unweighted mean of the five. Weighting them would imply a ranking nobody has evidence for, and inventing one is false precision. The components are published beside the score, because a single opaque number is not a governance artefact. An empty layer scores zero and reports it, rather than dividing by zero into a flattering hundred.
Set that beside the badge and the useful cases fall out on their own. Certified and well documented is the state you wanted. Certified and undocumented, with no named steward, is a badge holding up a claim that has nothing underneath it, and the fix is an afternoon, not an argument.
Keep the two senses of the word apart. Certifying content is a claim about fitness for use, made by a named person. A compliance certification is a different thing entirely, and the scanners here say so in their own emitted output: the security posture summary is stamped as audit evidence mapped to CIS Controls v8.1 and NIST CSF 2.0, requiring human verification, and the risk methodology says the same about its score. Keeping the two apart costs one sentence in a note and saves a long half hour in an audit.
A re-certification review that fits in an hour
Quarterly, and short enough that it actually happens.
List every certified data source with its note, its owner and the date it last changed.
Strike out every note containing nothing checkable. Those are the ones to redo first, because they are the ones nobody can defend when asked.
For what remains, confirm the person named in the note is still there and still owns that subject.
Compare each one against its previous version and read only the meaningful differences.
Record the outcome, including the ones that passed. A list of failures alone can never show coverage.
Where a certification is retired, say so in the note and leave the date. Better a withdrawn claim with a reason than a badge that quietly disappeared.
What comes out is a short list of data sources whose badge and evidence agree, and a shorter list to re-certify properly. Both beat the alternative, which is a badge nobody has looked at since the day it was set and everybody has been quoting ever since.
Four things get called governance: certification, ownership, stale content and change control. Here each one is written as a check you can run, not an aim you can state. It also covers the one change that passes a visual review and is still wrong.
An assertion is a sentence. Evidence is something a second person can check without asking you. What an audit trail has to contain, what a hash actually proves, and what to require of any tool that claims to produce one.
A permission question is asked like a lookup and behaves like a calculation. The inputs, the order they resolve in, why the answer takes six screens to reach, and what a read-only layer can tell you about it without touching anything.