Four things get called governance: certification, ownership, stale content and change control. Here each one is written as a check you can run, not an aim you can state. It also covers the one change that passes a visual review and is still wrong.
Most Tableau governance documents set out aims. Content will be certified. Owners will be kept current. Unused dashboards will be retired. Each of those is reasonable. None of them can be enforced in that form. None names the check that would prove it.
A control has three parts. A rule stated tightly enough that it can fail. A tool that applies the rule. A record of what happened when it did. With all three, you can be audited on it. With only the first, you have written down a preference.
Everything below is written as a check. A check is a thing you can run on a Tuesday. It is also a thing you can hand to someone on a Friday.
What a certified badge claims
A certified data source is a claim by a named person. It says this thing is fit to be used. It does not say the numbers are correct. Treating it that way is how certification quietly loses its meaning inside about eighteen months.
Three questions keep the claim alive: who certified it, against what, and when. If the certifier has left, the claim has no author. If nobody wrote down what the check was, the badge means someone clicked a button.
Certify data sources, not dashboards. A dashboard takes its trust from what feeds it, so certifying the dashboard certifies the wrong object.
Record what the certification asserts, even if that is one sentence in the description field.
Re-check on a cadence, and let a lapsed check read as expired.
Certifying everything tells you the same as certifying nothing. The signal is the contrast, and a site at one hundred percent certified has thrown the contrast away.
Ownership carries the weight
Every governance question ends at a person. Who approves this change. Who gets the call when it breaks. Who answers when it turns out to show something it should not.
Six kinds of object carry an owner: workbooks, published data sources, flows, projects, subscriptions and refresh tasks. Ownership is set per item. One person leaving therefore leaves a scatter of items, not a single account to deal with.
Two ownership checks are worth running each month. The first finds content owned by a user who is no longer active or licensed. The second finds content owned by an account that is not a person. A service account counts, and so does the admin who happened to run the last migration.
Measuring stale content
Stale is not the same as unused, and neither is the same as wrong. Three separate signals, worth keeping apart.
Last viewed
Nobody has opened it lately. Cheap to measure, and the weakest of the three. A quarter-end dashboard is used four times a year and should stay.
Last refreshed
The data behind it has stopped updating. This one is stronger, because what people see is old even on the days they look at it.
Last maintained
Nobody has edited it, and its owner is inactive. This is the one that predicts a question nobody can answer later.
The risky pair is viewed often and refreshed never. Those dashboards get quoted in meetings while showing last quarter. They are also the ones that make people doubt the whole platform when someone finally notices.
Extract staleness is invisible in the workbook file. Catching it takes a comparison of the numbers actually served. A perceptual hash of the rendered view catches one more case, where the structure is identical and only the picture differs.
Comparing two saves
Tableau rewrites the workbook file on every save. Identifiers are made afresh, attributes move around, whitespace churns. A text diff of two saved workbooks is almost all noise. That is why file-level version control feels useless on this kind of content. It is also why teams give up on it.
The comparison that works is model to model. Match fields by their internal name, which holds steady across caption renames and reordering. Report only the differences that carry meaning. In practice that is twenty-four kinds of semantic difference. Three of those always fail rather than warn.
One is worth memorising. A calculated field is removed, and a direct database field with a similar caption takes its place. The dashboard still renders. Every label is the same. The number is now something else. That change passes a visual review every single time, which is exactly why it is never dismissible.
What a check leaves behind
Who ran it, and when.
What it compared, named clearly enough that someone else could run it again.
The result, including the checks that passed. A report of failures alone cannot prove coverage.
Any waiver, with the person who granted it and the date they did.
Waivers are the part worth getting right. A finding that can be clicked away leaves no trace of the decision. A year later, nobody can tell an accepted risk from one nobody noticed. A recorded waiver is a governance artefact in its own right. It says a named person looked at this, understood it, and accepted it on a date.
The order to work in
Fix ownership first. Every later check has to report to someone, and a finding with no addressee is noise.
Inventory what exists, including the subscriptions and refresh tasks that never show up in a project tree.
Scan for exposed personal data and security risk before you tidy. Tidying moves content, and moving content changes who can see it.
Certify a small number of data sources properly, not a large number loosely.
Retire content last, with the last-viewed and last-refreshed evidence attached to the request.
Done in this order, each removal arrives with its own argument. Done in the other order, the argument happens live, with a director whose dashboard has gone.
An assertion is a sentence. Evidence is something a second person can check without asking you. What an audit trail has to contain, what a hash actually proves, and what to require of any tool that claims to produce one.
A person leaves. Their name stays on workbooks, schedules and subscriptions, and several of those fail without a sound. What they hold, what breaks, and the order that keeps the license recoverable.
Content is the easy part of a migration. This is what has to move with it, what tends to break quietly afterwards, and what a governed migration checks before anyone approves a run.