Salesforce Tableau Platform
Tableau is a leading visual analytics platform transforming raw data into interactive, shareable dashboards. Its low code/no code interface facilitates quick visualization creation. Key features include flexible deployment (cloud/on-premises), real-time collaboration, built-in AI (Ask Data/Explain Data), robust geospatial mapping, and powerful statistical analysis for in-depth insights.
Features
- Advanced Visualization: Renders interactive charts for high-performance visual analysis.
- Connectivity: Connects hundreds of databases, cloud sources, and bigdata.
- Flexible-Data Modes: Offers live or in-memory analysis.
- Custom Calculations: Simple expressions and formulas for customisation.
- Geospatial Mapping: Built-in geographic data for location-based visualization.
- No-Code Interface: Drag-and-drop functionality queries data easily.
- Data Integration: Joins disparate data sources into a single view.
- Tableau Prep: Cleans, shapes data, and handles ETL processes.
- Secure Deployment: Server or Cloud deployment for any data classification.
- Augmented Analytics: AI uses natural language for explanations/modeling.
Benefits
- Gain Insight Faster: Quickly explore large datasets for rapid understanding.
- Make Better Decisions: Empower staff to make informed, objective choices.
- Boost Collaboration: Securely share interactive dashboards across your entire organization.
- Analyze Independently: Perform powerful analysis without needing specialized IT assistance.
- Increase Agility: Rapidly adapt reporting and analysis to market conditions.
- Ensure Consistency: Govern data centrally so everyone uses trusted metrics.
- Manage Growth: Scale the platform easily as demands increase.
- Strengthen Security: Centrally manage security policies and permissions for compliance.
- Lower Costs: Reduce reliance on specialized reporting staff and development.
- Drive Culture: Foster curiosity, exploration, and informed decision-making.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 1 8 0 6 9 1 5 1 8 8 5 7 9
Contact
INSIGHT DIRECT (UK) LTD
Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Location and geospatial data management and analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Elements of Tableau can be found within Salesforce CRM software for use cases where data is pushed to users (instead of data exploration/ exploitation), such as call centre agents, in the flow of work.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- No specific constraints. there are hardware specifications that are recommended for server-based deployments, but it doesn't invalidate any support.
- System requirements
-
- Windows 10+ 64-bit or macOS Ventura or newer required.
- Dual-core CPU minimum; i3 or Ryzen 3 equivalent.
- 4 GB system memory minimum for Desktop operation required.
- 2 GB free disk space needed for software installation.
- 128 GB system memory recommended for server performance optimisation.
- 50 GB free disk space; SSD storage highly preferred.
- Windows Server 2016+ or Linux x86-64 distributions required.
- 64-bit operating systems required for all Tableau installations.
- Minimum Browser versions: Chrome, IE(v11), Firefox, Safari (iOS8.x)
User support
- Email or online ticketing support
- Yes
- Support response times
- Tableau support times are based on severity and your service plan. For the highest tier, 'Signature Support', critical Severity 1 issues receive a target initial response within just 15 minutes (24/7/365), and urgent Severity 2 issues within one hour. Customers with 'Standard' or lower tier plans will experience longer response times, from 1-4 hours, to 1-5 business days for non-critical cases during standard business hours.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Not aware of any specific testing that has been undertaken by Tableau. The web chat itself though is generic, not exclusive to Tableau so likely to have been subjected to such testing elsewhere
- Onsite support
- Yes, at extra cost
- Support levels
-
The Tableau support model, integrated with Salesforce, is delivered through tiered 'Success Plans', with costs tied to the overall license spend.
Support Levels and Cost
- Standard Success Plan: Included with all Tableau licenses. It provides self-service resources and online case submission during standard business hours.
- Premier Success Plan: An optional, paid upgrade (a percentage of license spend). It offers significantly faster response times (e.g., Severity 2 target of 2 hours 24/7) and access to 'Expert Coaching' sessions.
- Signature Success Plan: The highest premium tier. It guarantees the fastest possible response times (Severity 1 target of '15 minutes' 24/7) and proactive monitoring of your environment where possible.
Dedicated Technical Resources
- Designated Customer Success Manager (CSM): The 'Signature Success Plan' is the only tier that includes a dedicated CSM, who acts as your personalized advocate for strategic guidance, who coordinates an extensive team of specialists from across the support organisation, from 'Expert Coaches', deep technical engineers, product / UX specialists to executive engagements. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Tableau provides a great deal of training material and supporting collateral that is publicly available on the web. In addition, we have a range of training courses that cover use and administration of the software. For example: Free training videos, free online training presentations, e-learning, classroom-based courses, on-site courses and virtual courses.
Another relevant aspect here is the huge community of partners, users, fans and collaborators across the world who regularly support Q&A forums and provide blog articles and other information that contributes to a collective body of knowledge that our customers find very valuable as they are developing their own skills.
In addition to this, Tableau can be engaged to provide Professional Services for a fee, with a bespoke engagement defined and conducted in accord with the customer's requirements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users have full control over the content (including published workbooks and data extracts) that they choose to put into the Tableau Platform and they can regenerate, drop, download or retract these at any time.
Users can request a full copy of their data at the end of their contract which they could then restore to a local server if required.
As stated in our Terms of Service, once a Site is terminated all data, content and related metadata will be removed and is not recoverable. - End-of-contract process
- No additional cost. At the end of a subscription period, if a customer does not renew, then they will find their license is no longer active and all users in the organisation will be unable to publish, access or interact with any content in their Tableau Site.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Published Tableau content can be accessed and edited via a web browser running on any PC or device. The user experience and interaction is defined by the Creator who published.
In addition, Tableau provides a free mobile App so that when users access published content from iOS or Android devices the interaction and display is adapted to suit the touch-screen experience. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The Tableau service interface is built around two primary environments:
- Tableau Desktop: A powerful, drag-and-drop authoring environment where users connect to data, build visualizations, and design interactive dashboards. Its intuitive 'VizQL' engine translates visual actions into analytical queries.
- Tableau Server/Cloud: A web-based platform used for viewing, interacting with, and collaborating on published dashboards via a standard browser interface. It allows users to easily share, govern, and perform web authoring using simplified controls.
The overall design is highly visual, prioritizing ease of use and rapid analysis over complex coding. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- No specific testing of assistive technology for the portal
- API
- Yes
- What users can and can't do using the API
-
Tableau provides two core APIs for automation and data control.
The 'REST API' enables extensive server and site management, allowing users to automate administrative tasks such as provisioning users, managing groups, controlling permissions, and querying metadata. For content, it facilitates the programmatic publishing, updating, and deletion of workbooks and data sources, alongside triggering and monitoring extract refresh jobs.
The 'Hyper API' focuses purely on data management within Tableau's optimized `.hyper` extract files. Users can perform full CRUD (Create, Read, Update, Delete) operations, automate custom ETL processes, and build custom data connectors.
APIs have limitations: they cannot directly edit the visual structure, charts, or filtering logic inside a published workbook or dashboard. They are designed for automation and management, not for real-time end-user interaction. Additionally, Tableau Cloud environments enforce strict rate limits (throttling) on API calls to manage server performance. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The purpose of the Tableau Platform is to allow customers to create their own visualisations/ visual analytics, reports and dashboards, to tell the appropriate story of their data, to make an informed decision.
Because Tableau is a literal blank canvass, each visualisation is customisable to the users who will use the asset - from standard charts, reports, to data science/ statistical work, geospatial and a wide variety more.
Scaling
- Independence of resources
- Tableau offers flexible deployment: On-premises installation gives clients full control, while Tableau Cloud (SaaS) is securely hosted and maintained by us. For Cloud users, we proactively monitor activity, dynamically guaranteeing sufficient processing power to prevent performance degradation during peak usage. We maintain high service standards and transparently publish a daily report detailing historic service availability and planned maintenance schedules.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Tableau Site Admins access service metrics via Administrative Views, TSM, and the PostgreSQL repository. Usage metrics track content popularity (Traffic to Views), user actions, and data source utilization. Performance metrics monitor environment health using TSM to check server process status (CPU/memory), extract refresh success rates, and dashboard load times. For advanced audits, the PostgreSQL repository provides granular governance data, including license status, comprehensive permission records, and detailed user activity for compliance and in-depth analysis.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Salesforce Inc.
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- By default, all data is encrypted at rest with AES 256 using the AWS encryption.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Tableau will connect to your own data where it resides, so it is unlikely there will be any data extraction necessary from the service. On termination, the visualisations will be inaccessible.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- TDE
- HYPER
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Microsoft Excel (.xlsx): Common spreadsheet format for desktop data analysis
- Comma-Separated Values (.csv): Plain text for quick simple transfer.
- Tableau Extract (.hyper): Optimized fast compressed Tableau proprietary data format.
- JSON Files (.json): Standard format for web data NoSQL documents.
- Spatial Files (.shp): Geographic data formats for map location visualization.
- Server and Web Sources SQL Databases: Connects to relational databases.
- Cloud Data Warehouses (Snowflake): Optimized connections to cloud-based analytical platforms.
- Google Analytics: Native connector for web traffic performance data analysis.
- Salesforce CRM: Deep integration to analyze customer and sales data.
- ODBC/JDBC Connections: Generic drivers connecting to almost any data source.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The Salesforce Services are designed with the concept of continuous improvement and Trust (e.g. Availability, Performance and Security) in the infrastructure. Salesforce uses commercially reasonable efforts to make its on-demand services available to its customers 24/7, except for (minimal) planned downtime, for which Salesforce gives customers prior notice, and force majeure events. This service leverages Public Cloud region, and uses multiple availability zones. This pattern allows services to withstand up to two different zonal faults and continue to be available. Live and historical statistics on Salesforce system performance are publicly published at: https://trust.salesforce.com/en/#systemStatus.
- Approach to resilience
- Salesforce Hyperforce based cloud services has its compute resources run in 3 Availability Zone (AZ). Services run as containerized applications in containers which is configured for HA (high availability) by distributing nodes across AZs. To take advantage of this, service pods themselves are deployed across AZs when scheduled on nodes. Because of this when one AZ goes offline there will always be available service pods in different AZs to handle the workload. Service pods are also stateless so losing an AZ and nodes in that AZ along with the service pods running in them will cause no loss of data and new service pods will be scheduled on the available zones to handle the load.
- Outage reporting
- Outage escalation policies are established and maintained as Salesforce's goal is to rapidly restore service. In the event of an extended outage, periodic updates are provided in near real time to customers via the trust.salesforce.com dashboard site and in addition, service notifications are provided to nominated contacts via various channels such as email. Update frequency for notifications is dependent on the customer support service plan.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Management access for service support and delivery is done through multiple layers of controls including, but not limited to, multiple 2 factor authentication, just-in-time access, access related to an approved trouble ticket and segregation of duties. These controls are in scope for SSAE-18 auditing and evidenced through the SOC 2/ISAE3402 report.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
-
Administrative access to Tableau-managed systems is restricted to a small number of trusted individuals. Access Is reviewed and approved on a quarterly basis. Remote access to the production environment is only permitted through hardened SSO domains that require two-factor authentication using SSO's Advanced Server Access (ASA).
To obtain Administrator access, the employee must meet the prerequisites, they must submit a ticket with the requested level and business justification, acquire approval from the associated area, and only then will be provisioned access.
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 27017
ISO 27018
SOC 1,2, 3
UK Binding Corporate Rules - Information security policies and processes
-
Salesforce's Information Security Management System (ISMS) and information security policies are based on the ISO 27002 framework of best practices and are ISO 27001 certified.
As required by this certification, the ISMS is endorsed by Senior Management. The Chief Trust Officer/CISO has responsibility for the information security policies and ISMS. The Salesforce Security Steering Committee approves/authorizes all changes to the policies, the Statement of Applicability (SoA), the information security manual, and any separate policy statements.
During the ISO 27001 audit process (as well as other audits such as SOX and SSAE 16 SOC 1), senior management for various departments are involved in verifying that policies and procedures are in place and adhered to. Policies are reviewed/approved at least annually.
Companywide security awareness training highlights the importance of the security policies to employees and reinforces the company’s number 1 value of Trust. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes to infrastructure components are made through code using industry standard Infrastructure as Code (IaC) software and assessed for their security impact before being deployed. Individuals who wish to deploy an IaC change into production are required to follow defined procedures and standards, and to complete mandatory change management training before participating in the change management process. A change must be approved and routed through the change owner before the change can be implemented. A ticketing system is used as part of the change management procedure which records the components and the changes made.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Salesforce includes threat modelling into its software development lifecycle to help ensure the risks associated with potential threats are mitigated as early as possible. Multiple threat intelligence sources are used to help understand the current and evolving threat landscape.
Vulnerability scans are performed on all Salesforce information systems and hosted applications. Patches are deployed in timeframes based on CVSS scores and risk level.
All vulnerabilities discovered during penetration tests are entered into the salesforce central ticketing system and are assigned an internal vulnerability ranking according on the OWASP risk rating framework based on likelihood and impact. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Salesforce Threat Intelligence and Detection team monitors the Salesforce services 24x7 for threats and unauthorized intrusions in collaboration with the Security Incident Response teams. Extensive logging and monitoring is conducted across all Salesforce Services and environments (at application, network and database layers). All suspicious activities are flagged and reported to Salesforce CSIRT for investigation, management, communication, and resolution of security events and incidents in line with the NIST Incident Response model.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Salesforce has an Incident Management Process that guides the Salesforce Computer Security Incident Response team in investigation, management and resolution activities which includes developing standard pre-defined procedures for dealing with common events.
Salesforce will promptly notify the customer in the event of any security breach of the Service resulting in an actual or reasonably suspected unauthorized disclosure of Customer Data. Notification may include phone contact by Salesforce support, email to customer's administrator and Security Contact and public posting on trust.salesforce.com.
Customers can email security@salesforce.com or use the https://security.salesforce.com/contact page to report incidents. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Please contact us for the link.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Atlas
- ISO/IEC 27001 accreditation date
- Sunday 13 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Atlas
- ISO 9001 accreditation date
- Tuesday 1 April 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Be7ce590-de10-486e-8431-2e10891a8979
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-