TECHNOLOGIES: TABLEAU

Tableau Security Review

An embedded password on a Tableau data source can give every viewer the publisher’s own access. We test site roles, permissions, row-level security and embedded credentials. CREST-certified testers, fixed price from £3,280 for a 2-day single-site scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Tableau Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
1 password

A workbook author who chooses Embed password when publishing a data source hands every viewer of that workbook their own Connect access, and Tableau’s documentation confirms this directly.

One embedded password can hand every viewer of a Tableau workbook the publisher’s own data access

Tableau’s own site role table shows the two roles with full connect-and-publish rights, Site Administrator Creator and Creator, sit above Explorer (Can Publish), which has limited publishing capabilities, and Explorer, Viewer, Read Only and Unlicensed, which cannot publish at all. Underneath that, every project, workbook and data source carries its own permission rule for each capability, set to allowed, denied or unspecified, and a project’s Asset permissions setting is either Locked, so every nested item inherits one uniform rule, or Customizable, so an individual workbook can carry different rules from its own project. We map who actually holds each site role and where a project has quietly gone from Locked to Customizable against what your business intended.

Publishing a workbook against a published data source means choosing between Embed password, using the author’s own Connect access to that data, or Prompt users, requiring each viewer’s own credentials, and Tableau’s permission capability reference is direct that embedding a password means the author is essentially embedding their own Connect capability for anyone who opens the workbook. A separate Download Data Source capability lets a user take the whole data source away as a TDSX file, at which point every embedded credential travels with it. We test which authentication choice is live on every published workbook and data source in scope, and who can walk away with the file entirely.

Row-level security in Tableau runs through a user filter mapped manually or built dynamically against a reference security or entitlement table, but it only restricts data when the filter is set at the data source level, not the workbook or sheet, and a centralised alternative exists in a virtual connection’s data policy, which applies its own policy condition against an entitlement table across every workbook built on it, the equivalent layer we test on our Power BI and Snowflake reviews. Embedded analytics adds another identity to check, since a connected app’s JWT names the connected app and the user a session is generated for, and we confirm that identity is genuine rather than shared or over-scoped, alongside whether a Guest user account, a Tableau Server feature tied to core-based licensing, is quietly live on a deployment that should have none.

SCOPE

What we review in a Tableau site

TB-01

Site roles: what each level of access actually allows

Tableau’s site role table gives full connect-and-publish rights only to Site Administrator Creator and Creator, limited publishing to Explorer (Can Publish) and Site Administrator Explorer, and no publishing at all to Explorer, Viewer, Read Only or Unlicensed. We test who actually holds each site role against who the business meant to grant Creator-level access.

TB-02

Project and data source permission rules, and locked projects

Permissions run per content type, project, workbook, data source and more, as capabilities set to allowed, denied or unspecified, and a project’s Asset permissions setting is either Locked, so nested content inherits one uniform rule, or Customizable, so an individual asset’s rules can diverge from its project. We test whether every project’s actual lock state and rule set matches what was intended, not just what one workbook’s publisher set on the way in.

TB-03

Row-level security: user filters and entitlement tables

Tableau’s documentation sets out two approaches to user-based row-level security: mapping users to values manually in a user filter, or a dynamic filter built from a calculated field against a reference look-up, entitlements or security table in the underlying data. Its permission capability reference also confirms a user filter only enforces security when it is set as a data source filter rather than a workbook or sheet-level one, so we test where every RLS rule actually lives, not just that one exists.

TB-04

Row-level security: virtual connections and data policies

A virtual connection can carry a data policy that filters shared tables using a policy condition tied to an entitlement table, giving one centrally managed row-level security rule that data source-level user filters can’t provide on their own. We test whether the policy condition and the entitlement table it maps to actually restrict every workbook and flow built on the virtual connection, the same layered review we run for Power BI’s RLS model.

TB-05

Embedded data source credentials: who a workbook really connects as

When publishing a workbook against a published data source, the author chooses between Embed password, which Tableau’s documentation confirms effectively embeds the author’s own Connect capability for every viewer, or Prompt users, which requires each viewer’s own credentials. We test which option is live on every workbook in scope, and whether an embedded password is quietly handing out access nobody individually holds.

TB-06

Embedded analytics: connected apps, JWT and who the embed runs as

Tableau connected apps establish trust with an external application through either direct trust, where the application signs a JWT naming the connected app and the user the session is generated for, or OAuth 2.0 trust through an identity provider, and Tableau’s documentation is explicit that Tableau connected apps and Salesforce connected apps are different products with different functionality. We test what identity and access an embed’s JWT actually carries, and whether it matches the end user it claims to represent.

TB-07

Extracts: what a downloaded copy actually contains

A Tableau extract is a subset of the source data saved separately for performance, capable of holding data at large scale, and refreshed either in full or incrementally, per Tableau’s documentation. We test whether an extract’s own filters actually match the row-level security applied to the live connection it was built from, and who can download that extract as a standalone file.

TB-08

Download and export permissions on views and data sources

Separate capabilities govern export: Download Image/PDF, Download Summary Data (the aggregated marks as a CSV), Download Full Data (the underlying view data as a CSV), and on data sources, Download Data Source, which lets a user take the entire data source away as a TDSX file. We test which of these a role actually holds against what your data classification intended, since Download Full Data and Download Data Source each bypass the view a dashboard was designed to show.

TB-09

Personal access tokens for REST API access

Personal access tokens let a user sign in to Tableau’s REST API without hard-coded credentials or interactive sign-in, and Tableau’s documentation recommends them specifically so a compromised or misused token can be revoked without touching the user’s own password. We test where PATs have been issued, whether they’re scoped to the automation that needs them, and whether stale or over-privileged tokens are still live.

TB-10

The Guest user account, and Tableau Cloud versus Tableau Server

Guest user access is a Tableau Server feature enabled by default under a core-based licence, and Tableau’s documentation states it is not available with user-based licensing, letting people view content with no account of their own while only ever reaching data that carries embedded credentials, never a data source that prompts for one. We confirm during scoping whether your deployment is Tableau Server or Tableau Cloud and whether Guest access applies, then test it against the same embedded-credential and permission rules as every named account.

OUR PROCESS

Tableau Security Review: From Scope to Attestation

01

Site, Role and Permission Mapping

We list every site role, project, workbook and data source permission rule, plus the current Locked or Customizable asset permissions setting on every project in scope.

02

Row-Level Security and Data Policy Testing

Every user filter, entitlement table and virtual connection data policy is tested against real logins, and we confirm each RLS rule is defined as a data source filter rather than a workbook or sheet-level one.

03

Embedded Credential, Connected App and Extract Testing

We test which workbooks embed a data source password, what identity a connected app’s JWT actually carries into an embed, and whether extracts hold rows the live connection’s row-level security would otherwise have filtered out.

04

Reporting and Retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Tableau pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Tableau Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,280–£4,820
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£7,710–£11,740
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Tableau Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need?

Site Admin access to the Tableau site under test, or at least project leader or Explorer (Can Publish) access to every project in scope, plus a login for each site role or user filter group you want row-level security tested against. Read access to any virtual connections and their data policies speeds up confirming what we find.

Will you touch our live data?

We test read-only against production by default. Where proving a download capability, an embedded credential or an extract’s contents needs real records, we agree a specific dataset or test site with you first, and anything we create during testing is documented and removed afterwards.

Is this hosted on our infrastructure or Salesforce’s?

Tableau Cloud runs entirely on Salesforce’s infrastructure, so there’s nothing of the platform itself to host or test. If you run Tableau Server on your own infrastructure instead, the server and its host form a separate scope we agree with you first; either way, this review is scoped to your site’s roles, permissions, row-level security, embedded credentials and connected apps, not the underlying Tableau product.

Does this cover Tableau Desktop or Tableau Prep?

No. This page is scoped to a Tableau site, its projects, workbooks, data sources, virtual connections, extracts and connected apps. Tableau Desktop and Prep Builder are client installations used to author content and sit outside this scope.

What is out of scope?

Salesforce’s own infrastructure, other sites within your Tableau Cloud tenant, denial-of-service testing, and Tableau Desktop or Prep Builder client software are all out of scope here.

Is penetration testing our own Tableau Cloud site allowed under Salesforce’s rules?

Salesforce operates Tableau Cloud and publishes security testing terms for its platforms, but the detail and scope can change and can vary by product. We confirm Salesforce’s current customer security testing terms for your Tableau Cloud site with you during scoping, and test only within whatever authorisation that process requires. If you run Tableau Server on your own infrastructure instead, that authorisation is yours to give directly.

How long does a Tableau test take?

A single-site engagement covering a handful of projects and row-level security approaches typically runs to a 2-day scope. More projects, virtual connections or connected apps configurations extend it, and we confirm the exact day count once we’ve seen the site.

Do you need admin access to Tableau Cloud Manager?

No. Site Admin access to the relevant site or sites is enough to start. Tenant-level access through Tableau Cloud Manager speeds up confirming cross-site settings but isn’t required.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Tableau site

An embedded password on a Tableau data source can give every viewer the publisher’s own access. We test site roles, permissions, row-level security and embedded credentials. CREST-certified testers, fixed price from £3,280 for a 2-day single-site scope, quoted within 24 hours.