Salesforce

Tableau

Included as a governed analytics surface whose MCP can query published data sources through VizQL Data Service, ground agents with Tableau metadata, retrieve workbooks, views, images and Pulse insights, and expose selected site operations under existing Tableau identities, permissions, tool configuration, and content scope.

Analytics, SEO & experimentationSystem of intelligenceExtensible SaaS
An illustration of access surfaces surrounding a governed system.
System roleSystem of intelligence
Access maturityExtensible SaaS
MCP supportOfficial MCP server
Reference updatedSep 2, 2025
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Published data sources and metadata; workbooks, views, images, projects and jobs; extract-refresh tasks; Pulse metric definitions, metrics, subscriptions and insights; Prep flows; Admin Insights; OAuth consent and tokens; site users and roles; deletable workbooks, data sources, and refresh tasks.

02 · Data you can retrieve

List and inspect published data sources, metadata, workbooks, views, projects, jobs, refresh tasks, Prep flows, users and Admin Insights; query supported published sources with VizQL; retrieve view images and data; search content; and generate governed Pulse insight bundles or briefs where the underlying service is available.

03 · Actions and write paths

Configured tools can update a Tableau Cloud extract-refresh schedule, change a user's site role, reset OAuth consent, revoke the current MCP token, and permanently delete a workbook, published data source, or extract-refresh task. Permanent deletion is admin-only and additionally gated by `ADMIN_TOOLS_ENABLED` and a request-time site-role check.

04 · Authentication and permissions

Hosted Tableau MCP at `https://mcp.tableau.com` uses OAuth 2.1 and each user signs in with a Tableau Cloud identity, preserving per-user permissions. Official self-hosting supports PAT, Connected Apps, Unified Access Tokens, OAuth, or passthrough authentication; users also need access to the target content and API Access for queried data sources.

05 · Monitoring, approval, and recovery

Use Tableau permissions plus MCP tool controls and content scoping. Administrators can include or exclude tools and constrain data sources, workbooks, views, projects, or tags; Tableau 2026.2+ supports per-site MCP settings. Keep admin tools off unless required and require explicit review for schedule, role, token, and permanent-deletion operations.

06 · Limits and caveats

Hosted MCP is for Tableau Cloud; Server and infrastructure-controlled deployments use the official self-hosted implementation. Tool capability depends on underlying Tableau services and user access: VizQL Data Service and data-source API Access are needed for queries, Data Catalog supports metadata grounding, and Tableau Pulse is unavailable on Tableau Server. Per-site MCP settings require Tableau 2026.2+.

Agent access

MCP support

Official MCP serverTableau-hosted MCP plus official self-hosted implementationCurrent managed service

Support: Official MCP server

Read scope: Query and inspect scoped Tableau data sources and metadata; retrieve workbooks, views, images, projects, jobs, tasks, flows and users; search content; and generate Pulse insights when the authenticated user, underlying service, and enabled tool set permit it.

Write scope: Current configured writes include Tableau Cloud refresh-schedule updates, user site-role updates, current-session consent or token actions, and admin-gated permanent deletion of workbooks, published data sources, or refresh tasks. Do not infer broader REST API writes as MCP tools.

Authentication: Hosted: OAuth 2.1 at `https://mcp.tableau.com` with individual Tableau Cloud sign-in. Self-hosted: configurable PAT, Connected App, Unified Access Token, OAuth, or passthrough authentication, with transport and credential handling determined by the deployment.

Approval boundary: Reads may run within the configured content scope. Before schedule changes, role updates, consent resets, token revocation, or content deletion, show site, authenticated user, tool, target ID, old and new state, and reversibility. Permanent deletion always requires explicit confirmation and should remain disabled by default.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility4
Portability3
Observability3
Documentation4

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Salesforce ships them.

Single-platform patterns

  • Executive Marcom narrative and dashboard cockpit
  • Executive insight brief
  • Experiment review board
  • Anomaly investigation room
Use in the brief builder →

Multi-platform compositions

  • Tableau + warehouse or semantic layer: executive insight brief
  • Tableau + CRM or lifecycle platform + work-management system: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

5 recorded sources
MCP / agent-role validationRepresentative source
https://github.com/tableau/tableau-mcp ↗

Tableau documents a managed endpoint at https://mcp.tableau.com using OAuth 2.1 and per-user Tableau Cloud permissions; the official repository also supports self-hosting.

Publisher updated
Sep 2, 2025
BYO-UI reviewed
Jul 12, 2026

Targeted first-party MCP/agent-role review; broader API inventory retained

HomepageSource inventory
https://www.tableau.com/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Webhooks / extensionsSource inventory
https://tableau.github.io/extensions-api/ ↗

First-party webhook, event, SDK, embedded-app, or extension documentation.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

GraphQL metadata / VizQL queryTargeted review
Introduction to Tableau Metadata API ↗

Tableau's GraphQL Metadata API queries content, schema, and lineage metadata; VizQL Data Service separately queries governed published data sources. This is not an unrestricted SQL endpoint to underlying databases, and…

Publisher updated
Jul 5, 2026
BYO-UI reviewed
Jul 12, 2026

Targeted first-party access review

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.