Recents, across the whole suite
Whatever you worked on last is one click away from wherever you are, and the feed is scoped to you.
The platform
Your own Tableau Personal Access Token opens every tool, showing exactly the content Tableau grants you.
Nothing changes until a person says so.
The AI reads, explains and proposes. Anything it suggests arrives as a card that routes into the same approval gate a person would use, with the same signature and dual-control rules. Publishing always creates a new copy and never overwrites your work.
One image, one published port. The whole suite comes up behind it.
The gateway starts and supervises every tool on the machine’s own loopback. Your platform team has one thing to deploy, one thing to watch and one thing to upgrade. Everybody else simply gets a login page. Both runtimes travel inside that image, because Migrate wraps Tableau’s own .NET Migration SDK and we would rather ship it than ask you to install it.
The security topology
What stands between the internet and your governance data, from the outside in.
TLS terminates at a hardened edge proxy. Certificates renew themselves. It is the only thing on the box the internet can reach.
A machine-learning web application firewall inspects every request before the platform ever sees it. Injection and traversal probes bounce off with a 403.
One supervised container fronts the whole platform. Your one login fans out server-side into every governed tool.
Every tool is bound to the loopback interface inside the box. Not one of them is reachable from the internet, ever.
Credentials rest encrypted with row-level security, on an isolated internal network that has no route to the internet.
Runtime secrets mount in memory only. Their names stay visible for audit. Their values never leave the box.
A Personal Access Token you created in Tableau, under your own name. Everything that happens afterwards is built on that one credential.
It is held in memory for the life of your session. It is never written to disk, never returned to the browser and never written into a log, and a test asserts each of those.
The gateway signs in to Tableau once, mints a session token and hands that to each tool. Your Personal Access Token stays exactly where it started.
The suite inherits your Tableau permissions and keeps no set of its own. What you can open here is what you can open in Tableau.
A Connected App JWT is a service credential: it extends the platform, powering embedded views and service integrations. Signing in stays a human act.
Whose credential, where it lives, what a log holds, and what the browser gets.
| Aspect | Answer |
|---|---|
| Whose credential | Yours. A Personal Access Token you created in Tableau, under your own name. |
| Where it lives | Server-side, in memory, for the life of your session. |
| What the browser gets | Non-secret details about your connection. The token itself stays behind. |
| What a log holds | The event. The token is kept out of every log. |
| What each tool receives | A minted session token of its own. |
| What you can see | Exactly the content Tableau already grants you. |
14 tools behind one login would be a filing cabinet if each one forgot you the moment you left it.
Whatever you worked on last is one click away from wherever you are, and the feed is scoped to you.
Switching tools keeps the tool you left running. Come back to it and your work is where you put it.
Open a second browser tab and the Agent is still in the same conversation.
The whole product speaks every one of them, front and back, down to the tooltips on the admin rail.
Dark mode is one click in your account menu, and it stays chosen: every page, every admin console, and the sign-in screen too. Both modes are built to AAA contrast, because a governance tool gets read for eight hours at a time by people who did not choose their eyesight.
Every administrative job has its own page, grouped the way an administrator already thinks.
| Console | Group | What it is for |
|---|---|---|
| Users | Identity | Add people, reset a password or an authenticator, and change what someone may reach straight away. |
| SAML / SSO | Identity | Connect any SAML 2.0 identity provider per email domain. Each client organisation signs in through its own. |
| SMTP / Email | Identity | The mail route TabTotal sends from: invitations, password resets and lifecycle notices. |
| Locked-In PATs | Credentials / Integrations | Personal Access Tokens held server-side and shown to nobody again, with expiry tracking and a warning 30 days out. |
| Connected Apps | Credentials / Integrations | Tableau Connected Apps, which let the suite mint short-lived embed tokens for live previews. |
| Data & AI Integrations | Credentials / Integrations | Your own Anthropic or OpenAI key per site, and every other outside service you connect. |
| Global MCP Server | Credentials / Integrations | The Model Context Protocol endpoint an outside AI client uses to reach this site, per domain and per site. |
| User App Matrix | Credentials / Integrations | Who may open which of the 14 tools, as one grid you read across in a glance. |
| Container Apps | Platform | The sidebar itself: which tools appear, in which category, in which order. Drag to arrange, and swap a tool in or out. |
| Script Manager | Platform | Every Script automation on this instance across every user, with the override to stop one or stop them all. |
| Enterprise Semantic Layer | Platform | Inherit your Salesforce Data 360, Snowflake, Databricks or Palantir AIP business layer. Answers come from the metrics you certified. |
| Semantic Models | Platform | What TabTotal has learned about each connected Tableau site: workbooks, data sources and schemas the Agent reasons over. |
| Tableau Backups | Platform | Tableau content backups, written into storage you own. |
| TLS Certificates | Platform | How the platform is secured on the wire: automatic Let’s Encrypt, or your own certificates. |
| Clustering HA | Platform | Worker VMs for high availability. Nodes enrol over keyed SSH, state replicates, and a standby takes over when the main node goes down. A failover costs you whatever the last replication had not yet carried. |
| System Status | Platform | This container and host, live: CPU, memory, disk, uptime, and a health check on every supervised tool. |
| Languages | Platform | Every translation the suite ships, in every language it speaks, and your own wording wherever you want it changed. |
| Alerts & Notifications | Observability | Thresholds you set, and mail to whoever must act, with the suppression that keeps one real problem from becoming a mail storm. |
| Metrics | Observability | Usage across the suite: who is working in which tool, and how your Tableau Environment is being governed over time. |
| Agentic Manager | Observability | The TabTotal AI Agent: per-user activity, token spend and the recent conversation trail. |
| Admin Audit | Observability | Every administrative change, appended and never edited: who did what, to whom and when. |
| Change Ledger | Observability | The hash-chained ledger of governed configuration changes, in a sequence your auditor can re-verify. |
| Application Logs | Observability | Logs from the gateway and all 14 children, filterable and exportable. |
| AI Logs | Observability | Every AI call the suite made: surface, model, tokens and outcome, with content redacted by default. |
| PAT & JWT Logs | Observability | Personal Access Token and embed token events across every user and site: minted, used and expired. |
Plain SHA-256, no secret key.
Every administrative change is appended to a record that is never edited: who did what, to whom and when. Governed configuration changes also land in the hash-chained ledger, with a content hash recorded before and after each one.
Your audit trail writes itself while you work.
Governed changes land in a hash-chained ledger using plain SHA-256 with no secret key, so your auditor can re-verify its integrity from the export with their own tools.
One token, one login, and the suite is on your real content in minutes.