Tableau Server → Tableau Cloud
Move to Tableau Cloud knowing exactly what you're moving — and what you're leaving behind.
TabShift is self-hosted and runs entirely inside your network — no data leaves. It crawls your whole Tableau Server estate, scores every asset, maps every dependency, and executes the migration in the only order that works.
- Self-hosted · Docker
- Runs inside your network
- Air-gapped tarball for public sector
- Zero telemetry
The demo
This is what your estate looks like when you can finally see it.
A synthetic Tableau Server estate. Click any data source to see what breaks if you retire it. Click any workbook for its score and the reasoning behind it. The graph renders a representative 40-asset slice so the structure stays legible.
| Asset | Type | Project | Score | Recommendation | Rationale |
|---|---|---|---|---|---|
| Sales Performance | Workbook | Sales Operations | 88 | Migrate | Viewed 340 times in the last 30 days by 88 distinct users; no blocking features found. |
| Enterprise Sales | Data source | Certified Data Sources | 82 | Migrate | Certified source feeding 14 workbooks across 4 projects; the single highest-dependency asset on the site — migrate first, in dependency order. |
| Executive Daily Brief | Workbook | Executive KPIs | 81 | Migrate | Opened every weekday morning by the ELT; migrate alongside Exec KPI Mart and verify the 6am refresh lands. |
| Regional Scorecard | Workbook | Sales Operations | 80 | Migrate | Weekly leadership review deck source; clean extract, standard charts. |
| Sales Daily Refresh.tfl | Prep flow | Data Platform | 79 | Migrate | Runs nightly and feeds the site's most-used data source; migrate it before the workbooks that depend on it. |
| Pipeline Health | Workbook | Pipeline Analytics | 79 | Migrate | Standing agenda item in Monday forecast calls; dual-sourced from Enterprise Sales and Pipeline Snapshot. |
| Quota Attainment | Workbook | Sales Operations | 77 | Migrate | Steady daily use by sales managers; single certified source, no custom SQL. |
| Exec KPI Mart | Data source | Certified Data Sources | 75 | Migrate | Feeds the Executive Daily Brief; refresh window must land before 6am ET — schedule it early in the cutover. |
| OTIF Scorecard | Workbook | Supply Chain Control Tower | 75 | Migrate | Daily supply-chain standup source; live Snowflake connection, no Bridge required. |
| GL Actuals | Data source | Certified Data Sources | 74 | Migrate | Month-end close depends on it; extract refreshes are healthy and its custom SQL parses cleanly. |
| Deal Desk Monitor | Workbook | Sales Operations | 74 | Migrate | Active approvals workflow depends on it; subscription schedules will need to be recreated on Cloud. |
| Shipment Facts | Data source | Supply Chain Control Tower | 73 | Migrate | Live Snowflake connection carries to Cloud without Bridge; two downstream workbooks, both active. |
| Forecast vs Actual | Workbook | Pipeline Analytics | 73 | Migrate | Finance and Sales Ops both subscribe; extract refresh chain must follow its two sources. |
| Revenue Bridge | Workbook | Finance Reporting | 71 | Migrate | Month-end staple; dual-sourced from GL Actuals and Enterprise Sales, so it migrates after both. |
| Headcount Planning | Workbook | HR Analytics | 59 | Review | Monthly HRBP review; verify the user-filter row-level security on Workforce Core before this follows it. |
| Pipeline Prep v2.tfl | Prep flow | Pipeline Analytics | 58 | Review | Active weekly schedule, but 87% output-field overlap with Pipeline Prep (copy) — consolidate before migrating. |
| Pipeline Snapshot | Data source | Pipeline Analytics | 57 | Review | Actively used, but fed by two overlapping Prep flows; consolidate the flows before repointing workbooks. |
| Commission Tracker | Workbook | Sales Operations | 57 | Review | Used monthly by a four-person comp team; heavy blending against a local Excel file that must move to a published source. |
| Workforce Core | Data source | HR Analytics | 56 | Review | Embedded Oracle credentials and row-level security on a user filter — verify entitlements survive the move before workbooks follow. |
| Churn Watchlist | Workbook | Pipeline Analytics | 55 | Review | Active but low-audience; duplicate of logic now standard in Pipeline Health — candidate to consolidate. |
| Win/Loss Explorer | Workbook | Pipeline Analytics | 52 | Review | Quarterly use, but its custom SQL references a table that doesn't exist in the Cloud-visible schema — fix before migrating. |
| Attrition Deep Dive | Workbook | People Dashboards | 51 | Review | Active analysis work, but it joins Workforce Core to a local extract of exit-survey data that must be published first. |
| Territory Planner | Workbook | Sales Operations | 49 | Review | Touched during annual planning only; owner confirms it's needed each October — migrate late in the wave. |
| Board Pack Q3 | Workbook | Executive KPIs | 48 | Review | Spikes quarterly around board meetings; confirm with the owner whether Q4 will reuse it before migrating. |
| Pipeline Prep (copy).tfl | Prep flow | Pipeline Analytics | 23 | Retire | 87% output-field overlap with Pipeline Prep v2 (redundancy flags at 80%) and no schedule since March — retire and keep v2. |
| Budget 2019 | Data source | Archive 2019 | 23 | Retire | No refresh since 2019 and both downstream workbooks are themselves unused; retire the chain together. |
| 2019 Sales Review | Workbook | Archive 2019 | 17 | Retire | Zero views in 14 months and the owner left the org in 2024; superseded by Sales Performance. |
| Legacy Shipping Report | Workbook | Logistics — Legacy | 15 | Retire | Zero views in 11 months; replaced by the OTIF Scorecard and blends against a decommissioned Access file. |
| Budget Review FY19 | Workbook | Archive 2019 | 14 | Retire | Zero views in 16 months; the FY19 budget cycle it reports on closed five years ago. |
| Intern Sandbox Copy | Workbook | FP&A Sandbox | 14 | Retire | A personal-space duplicate of Revenue Bridge with no viewers; delete rather than carry forward. |
| Daily Ops 2019 | Workbook | Archive 2019 | 12 | Retire | Zero views since 2023; its only data source is itself flagged retire. |
| FIN-SQL01 · SQL Server | Database | — | — | — | On-prem SQL Server reachable only inside the network; Cloud connections will route through Tableau Bridge. |
| Snowflake EDW | Database | — | — | — | Cloud-reachable warehouse; direct connections carry over without Bridge. |
| Oracle HCM | Database | — | — | — | On-prem HR system; extract-only today, Bridge required for live connections. |
| Sales Performance / Overview | View | Sales Operations | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
| Sales Performance / By Region | View | Sales Operations | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
| Sales Performance / Rep Detail | View | Sales Operations | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
| Daily Brief / Summary | View | Executive KPIs | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
| Daily Brief / KPI Trend | View | Executive KPIs | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
| OTIF Scorecard / Main | View | Supply Chain Control Tower | — | — | Views inherit their workbook's disposition; scored at the workbook level. |
Synthetic data, scored with TabShift's real weights and thresholds: Migrate ≥ 60 · Review 25–59 · Retire < 25 or stale. On your estate, a crawl produces this from your own site in minutes.
How it runs
Six stages, in the only order that works.
A crawl precedes a score, a score precedes a plan, and nothing migrates before its dependencies. Click a stage for what actually happens.
01 · Connect
Point TabShift at your Server URL with a personal access token. Credentials are encrypted at rest with a key that can live in a Docker secret outside the database, and the API never returns them to the browser. Only one port is published — the backend is unreachable from outside the Docker network.
02 · Crawl
A full REST API sweep across eight categories: projects, workbooks, data sources, views, Prep flows, flow runs, users, and virtual connections — with progress streamed live over SSE. Every completed category is checkpointed, so a crawl interrupted by a container restart resumes where it left off instead of starting over.
03 · Score
Every workbook, data source, and Prep flow gets a 0–100 score from five weighted dimensions: usage frequency, recency, audience, dependencies, complexity. Migrate at 60 and above, Review from 25, Retire below that — or anything stale for 90+ days. Each recommendation carries a written rationale, and a human override is recorded with its reason.
04 · Plan
Lineage comes from the REST API plus the free Metadata API — no Data Management license required — and if the Metadata API is off, the graph degrades gracefully and says so. Blast-radius analysis shows everything upstream and downstream before you retire an asset. A Bridge deployment plan classifies every data source, and eight pre-flight checks gate the run: Ready, Warning, or Will Fail.
05 · Migrate
Execution follows the dependency graph — data sources first, then the workbooks that use them, then flows. Workbook XML is repointed to the exact content URLs Cloud assigns on publish. Migration is additive-only: nothing on your Server is modified or deleted. Runs are resumable from checkpoints and self-throttle against Tableau Cloud's 40,000-call-per-hour API limit.
06 · Verify
Per-asset results come from the migration manifest, not inference — success, failed, and skipped are never conflated. A full source-vs-destination comparison diffs users, groups, projects, workbooks, data sources, and flows, and five branded HTML reports package the engagement for stakeholders.
In motion
Watch it work.



The heavy lifting
The hard parts of a migration, handled.
-
Lineage without the license
The full dependency graph is built from the REST API plus the free Metadata API — no paid Tableau Catalog or Data Management license. If the Metadata API is disabled on your Server, the graph says so instead of quietly showing less.
-
Prep flows → Snowflake SQL, never silently
Translates .tfl Prep flows into Snowflake CTE chains across eight step types. Every step is marked HIGH, MEDIUM, or LOW confidence; anything uncertain gets an inline TODO and lands in a review queue. A translation only reports complete when every step is HIGH.
-
Air-gapped for real
The offline tarball ships the container images, compose file, and start scripts. Content-Security-Policy locked to self, fonts self-hosted, zero telemetry — the only outbound traffic is to your own Tableau endpoints. Five branded HTML reports for consultant delivery.
-
Credentials treated accordingly
The admin token is argon2id-hashed, personal access tokens are encrypted at rest, and the encryption key can live in a Docker secret outside the database — with a mode that refuses to start in any weaker configuration. Secrets are never sent to the frontend.
-
Nothing is deleted, ever
Migration is additive-only and Retire is a recommendation, not an action — automated deletion is formally out of scope because public-sector buyers won't accept it. From the builder of TabLens, 2nd place at the Tableau Conference 2026 Hackathon; TabShift is its site-wide companion, built on the same standalone parsing architecture.
See your own estate in it.
The demo above is synthetic. The interesting version is the one with your projects in it — a crawl of your own Server produces it in minutes.
Book a walkthroughTabShift is built by Keith Troutt · keith@keithtroutt.com