Playbook · 6 minute read
How to Build a Tableau AI Agent
A Tableau AI agent queries certified published data sources through the VizQL Data Service and REST API as the requesting user, so certified definitions and permissions apply, translates natural-language questions into field and filter specifications, and returns results with the data source and a link to the relevant view. Certification and metadata quality decide whether it is trusted.
Tableau's governance is not in a single semantic layer the way some platforms have; it lives in certified published data sources, the calculations defined in them, the permissions applied to them, and the data catalogue that describes them. An agent that respects that structure produces answers consistent with the workbooks people already use. An agent that goes around it to the database produces answers nobody can reconcile. This guide covers building one that works through the governance, drawing on FISTA Solutions' AI agents delivery on analytics platforms. It complements how to build a looker ai agent and how to build an ai analyst agent.
What is the governed layer?
Certified published data sources. When a data steward publishes a source, defines its calculations, applies permissions and row-level filters, and certifies it, that source becomes the trusted basis for its domain. Workbooks built on it inherit the definitions; an agent should too.
| Source type | Suitability | Why |
|---|---|---|
| Certified published source | High | Stewarded, documented, permissioned |
| Uncertified published source | Low | Definitions unverified |
| Embedded workbook source | Very low | Not reusable, often undocumented |
| Direct database connection | None | Bypasses all Tableau governance |
The agent should be restricted to certified sources, and expanding its coverage means certifying more sources, which is stewardship work rather than engineering.
How does querying work?
Through the VizQL Data Service, which runs headless queries against published data sources: the agent specifies fields, aggregations, filters, and sorting, and receives structured results without building a visualisation. The REST API supplies metadata, data source details, permissions, and the ability to locate and link to views.
This combination lets the agent answer a question with a number and then point the user to the certified view that shows the same thing, which is the provenance pattern that builds trust.
How are permissions enforced?
By executing as the requesting user. Tableau supports impersonation with appropriate server configuration and user-scoped authentication, and the agent must use one of them so that data source permissions and row-level security apply as they would in the interface. Row-level security in Tableau is commonly implemented through user filters or entitlement tables, and both apply only when the query runs as the right user.
A service account with broad access querying on everyone's behalf returns rows the user should not see. That is the failure to design against first.
What grounds the agent?
The data catalogue and field metadata: data source descriptions, field names and descriptions, calculation definitions, and the certification status. Descriptions are the critical input, because an agent choosing between three fields with similar names needs to know what each means and at what grain.
Most Tableau estates have thin descriptions, and enriching them for the certified sources in scope is the highest-return preparation. It benefits human users at the same time.
How is freshness communicated?
Explicitly, every time. Published sources with extracts refresh on schedules, and a correct number from an extract that last refreshed yesterday morning is misleading if presented as current. The agent reads the last refresh time from the data source metadata and includes it in every answer, so the user knows what they are looking at.
How are questions translated?
Into field and filter specifications against a certified source, chosen using the catalogue metadata, with clarification on ambiguity. The agent returns the number, the source, the fields and filters used, the refresh time, and a link to a relevant certified view.
Ambiguity is common: which date field, whether a measure is net or gross, which of two similarly named sources applies. The agent should ask. The cost of a clarifying question is trivial next to the cost of a decision made on the wrong basis.
What should the agent not do?
Query the underlying database. Use uncertified sources. Publish, modify, or delete workbooks or data sources autonomously. Present numbers without provenance. Or aggregate across sources in ways the stewards have not defined, since that produces numbers no certified view can be found to support.
How is warehouse and server load managed?
Through query limits, timeouts, and monitoring of the agent's query volume. VizQL Data Service queries hit the underlying data or extract, and an enthusiastic agent can generate meaningful load. Row limits on results, timeouts on long queries, and a per-question cost view protect both the server and the budget.
How is it evaluated?
Against real questions with answers verified in Tableau. Measure source and field selection accuracy, filter correctness, and match with the certified view. Test as users with different row-level entitlements to confirm results differ correctly. Measure clarification behaviour on a set of deliberately ambiguous questions.
What does the build sequence look like?
Two to three weeks on certification and description enrichment for the sources in scope, which is stewardship work. One week on API access and user-scoped execution. Two weeks on question translation with the analytics team testing. One week on presentation with provenance and view links. Then coverage expansion as further sources are certified.
What goes wrong?
Database bypass. Uncertified sources in scope. Service account execution. Thin field descriptions. Freshness unstated. Silent disambiguation. And treating coverage expansion as an engineering task when it is a certification task.
How does this fit with Tableau's own AI features?
Tableau ships conversational and AI-assisted analytics capability, and where it fits the need it should be used rather than rebuilt. A custom agent earns its place when the organisation needs its own presentation inside the tools people already use, wants to combine Tableau results with data from other systems, needs evaluation against its own reference questions, or must control ambiguity handling and freshness disclosure precisely. The custom agent still queries certified sources; what differs is what surrounds the query.
Who owns coverage expansion?
Data stewards, not the engineering team, and this is the organisational point most projects get wrong. The agent can answer questions from certified sources; expanding what it can answer means certifying more sources with adequate descriptions, which is stewardship work. Projects that frame expansion as an engineering backlog stall, because the engineering is trivial and the certification is where the effort sits.
How FISTA Solutions helps
FISTA Solutions builds Tableau agents that query certified published sources through VizQL Data Service as the requesting user, grounded in enriched catalogue metadata, stating freshness and provenance with every answer, and expanding coverage through certification rather than bypass, through AI enablement, AI agents, and forward deployed engineers working with analytics teams. The record behind the approach is 150+ projects for 50+ companies with 99.9% uptime.
To make Tableau conversational without breaking its governance, message FISTA on WhatsApp, or read how to build an ai analyst agent.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01How does an agent query Tableau data?
Through the VizQL Data Service, which runs queries against published data sources headlessly with named fields and filters, and the REST API for metadata, permissions, and view access. Together they let an agent answer questions from governed sources without constructing a visualisation.
02What makes a data source suitable for the agent?
Certification, meaning a data steward has marked it as the trusted source for its domain, plus field descriptions, consistent naming, and defined calculations. Uncertified sources with undocumented fields give the agent nothing reliable to ground on and should be excluded.
03How are permissions enforced?
By executing as the requesting user, through impersonation with appropriate server configuration or user-scoped tokens, so that data source permissions and row-level security through user filters or entitlement tables apply exactly as they do in the Tableau interface.
04How is freshness handled?
By stating it. Extracts refresh on schedules, so the agent should read the data source's last refresh time and include it in every answer, because a correct number from yesterday's extract presented as current is a misleading answer.
05What should the agent not do?
Query underlying databases directly, bypassing Tableau's definitions and permissions; use uncertified sources; publish or modify workbooks autonomously; or present numbers without the data source, fields, filters, and refresh time that let a user verify them.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.