Skip to content

What AI should never do to your Tableau server

The approve to run rule, in plain words. The assistant reads, explains and proposes, and a person owns the write path. What that costs, what it buys, and three questions to ask of any AI feature.

Updated · 6 min read

Where the line sits

One design choice sits under every AI feature here, and no setting can change it. The assistant reads, it explains, and it proposes. The write path stays with a person. Each thing it proposes arrives as an approve to run card. That card deep links into the human approval gate already built into the tool that owns the action.

That is capability isolation, not instruction. A model told to leave writing alone can still be talked into it, because language is the surface an attacker has. A model built with no write path holds, however the request is phrased. The code to carry it out was never there.

The same rule holds across every governed Tool. Where a tool does write, a person has already signed for it at that tool’s own gate. In several of them a person signs twice.

This answers prompt injection

An assistant that reads your server reads text other people wrote. Workbook titles. Field descriptions. Comments inside custom SQL. Log lines. Any of it can hold a sentence written for the model to obey.

Where an assistant can act, each of those strings becomes an instruction channel. Anyone who can publish to your site can write one. Here the write path belongs to a person, so a planted sentence can only put a misleading answer on a screen. A reader sees it and decides what to do.

The difference in risk is large: at worst a bad sentence on a screen, never a deleted data source.

What the rule costs you

The cost is real and worth saying out loud. A control described only by its benefits reads as a slogan.

  • It is slower. Every action passes a person, including the dull ones nobody wants to read.
  • Bulk work belongs elsewhere. Twelve hundred workbooks to fix is a job for the deterministic engines, not a conversation, and an assistant asked to grind through it will disappoint you.
  • It stays literal. A tool that guessed what you meant and acted on it would demonstrate better.

For a governance product, all three are the right trade. You are accountable for your own environment. A product that acts there on its own initiative leaves that accountability exactly where it was, and adds an actor nobody can question later.

Deterministic by default

The rule has a stronger form: the default path runs with no model in it. Analysis is deterministic until somebody ticks a box, and the interface says so in its own words.

Nothing ticked: the analysis runs on the fast deterministic engine.

That is what turns a report into evidence. Re-run a quality check next quarter, get the same answer, and you can attach it to a decision. An answer that moves with the model version behind it cannot be reproduced. It is not evidence.

The Risk scanner goes further, and every path in it is deterministic. A scan that decides whether personal data is exposed has to be repeatable, and repeatable is the only defensible design. A detection you can reproduce is a detection you can act on.

Whose key, whose account

Whose key
Yours. You supply it for a session, or an administrator locks it to your site. It is encrypted at rest and never echoed back to a browser.
Which provider
The client layer speaks to more than one. Any endpoint that speaks the OpenAI API can serve it, including one you host yourself. The base URL is a parameter rather than a constant.
What is recorded
Call counts, token counts, which models ran, and cost, per user, in an admin console. The shape of the work.
What stays out of it
Cells returned by a data query stay out of the audit. The row count is the shape that is kept.

That last row is the question to put to any AI product you look at. Ask what the audit log stores. If the answer is the conversation, you now hold a second copy of your data. It sits in a system your data classification work never looked at.

Reading data, a separate question

An assistant that only reads can still read more than it should. Two boundaries handle that, and they work independently.

  • The credential. Every read runs on the signed-in person’s own Tableau credential, so the assistant sees what that person sees and nothing more.
  • The engine. SQL the model writes runs against a materialised local copy, with external file access switched off. A plain database connection of the same kind will hand back a local system file through its CSV reader. This one holds the line.

On top of both, a metric named in a question is checked against the stored contract before anything reaches a warehouse. One measure keeps one definition, whatever words the question used.

What it buys

  1. An answer you can check, because every number in it came from a query you can run again.
  2. A record of what was asked, including the requests that were turned down.
  3. A blast radius set by one person’s permissions, not a service account’s.
  4. A way to say yes to an AI feature where the honest answer would otherwise be no.

The fourth is the one that gets projects approved. Most teams are not choosing between a governed assistant and an ungoverned one. They are choosing between a governed assistant and nothing at all, and nothing at all is what they have been choosing.

Three questions worth asking

  1. Can it write. If yes, what stops it, and is that a code path or a line in a prompt.
  2. Whose credential does it read with, and does that credential carry more permission than the person using it.
  3. What does the audit store, and for how long.

Those three answers tell you more than any accuracy figure. Better still, somebody on your own team can check each one in an afternoon.