Offboarding a Tableau user without breaking Monday
A person leaves. Their name stays on workbooks, schedules and subscriptions, and several of those fail without a sound. What they hold, what breaks, and the order that keeps the license recoverable.
Content is the easy part of a migration. This is what has to move with it, what tends to break quietly afterwards, and what a governed migration checks before anyone approves a run.
Updated · 6 min read
A migration plan built from a list of project names is a plan built from a guess. Before anything moves you want an inventory of what exists, taken from the source server itself, with an owner against every item.
Six kinds of thing can be owned by a person on a Tableau site: workbooks, published data sources, flows, projects, subscriptions and refresh tasks. The first three are what people picture when they say content. The last three are where migrations go wrong, because they are invisible in a project tree and nobody notices they are missing until a Monday morning.
Record the identifier, not just the name. Names repeat across projects, get renamed halfway through a project, and are the reason a cherry-picked migration selects the wrong workbook. Selection keyed by LUID cannot make that mistake, and a parent project should be pulled in automatically when a child is chosen.
Content moves. The things around content mostly have to be present before it can land.
Identity is the ordering constraint that catches teams out. Content cannot be owned by somebody who is not there yet. The sequence is not negotiable even when the calendar would prefer otherwise.
The failures that hurt are not the ones that throw an error during the run. They are the ones that leave a dashboard visibly present and quietly wrong.
Every item on that list is discoverable before you migrate, and none of them is discoverable from a project tree. That is the argument for the inventory step, and it is the only argument that survives contact with a deadline.
A dry run that only validates credentials tells you the password is right. A useful dry run resolves the selection and then walks what the run would do, item by item, so the plan you approve is the plan that executes.
The Migrate tool runs the official Tableau Migration SDK on .NET 8 inside the same container as the rest of the suite. The migration itself uses the vendor-supported path rather than a re-implementation of it. A two-layer dry run precedes a hard approval gate with three enforced conditions.
Read the dry run in full. It is the last cheap moment in the project.
The approval is the moment a named person takes responsibility. The record of it has to outlive the project team. A compliance audit is built from three plain inputs: the plan, the final state of the run, and the approval metadata.
It is rendered twice from one record. JSON for ingestion into a governance system, Markdown for a human reviewer or an audit file. One record, two renderings. The machine copy and the human copy cannot disagree.
Credential names and secret values never enter that audit. Endpoints, site names and types are recorded. A test enforces it.
The honest end of a migration is a comparison, not a green status page.
The last step is the one worth the hour. A dashboard that renders is not the same as a dashboard pointed at the right source, and the difference is invisible from the front.
Ownership first is the step people skip, because it feels like a separate project. It is also the step that turns a two-week migration into a four-week one when it is skipped, and the reason offboarding and migration are the same discipline viewed from two ends.
A person leaves. Their name stays on workbooks, schedules and subscriptions, and several of those fail without a sound. What they hold, what breaks, and the order that keeps the license recoverable.
Four things get called governance: certification, ownership, stale content and change control. Here each one is written as a check you can run, not an aim you can state. It also covers the one change that passes a visual review and is still wrong.
An assertion is a sentence. Evidence is something a second person can check without asking you. What an audit trail has to contain, what a hash actually proves, and what to require of any tool that claims to produce one.