11.2 Publishing Workbooks, Data Sources & Flows

Key Takeaways

  • Show Sheets as Tabs provides navigation and affects whether permissions operate at workbook or view level.
  • Published data sources centralize reusable metadata and connections; embedded sources remain workbook-specific.
  • Unattended refreshes need usable stored credentials or tokens and a valid network path.
  • Publishing a flow output does not automatically certify it; certification is a separate authorized governance action.
  • Tableau Server defaults to 25 retained revisions, while Tableau Cloud retains up to 10.
Last updated: September 2026

11.2 Publishing Workbooks, Data Sources & Flows

Publishing moves content from an authoring environment into Tableau Server or Tableau Cloud so people can discover, view, edit, refresh, and govern it. Before publishing, remove unused sheets and fields where appropriate, confirm names and descriptions, test permissions with representative groups, validate credentials, and decide whether connections should be embedded in a workbook or managed as published data sources.

Publishing a workbook

From Tableau Desktop, choose Server > Publish Workbook, select the site and project, name the workbook, choose which sheets to publish, configure permissions, and review data-source authentication. Hidden worksheets that feed dashboards normally remain available to the workbook even when not exposed as navigation destinations. Test the published result because fonts, extensions, credentials, and network reachability can differ from Desktop.

The Show Sheets as Tabs setting provides workbook navigation and changes permission granularity. When tabs are shown, views in the workbook use workbook-level permissions. When tabs are hidden and the project allows customizable permissions, views can be assigned independent permissions. Tabs should be selected for navigation and permission intent—not on an unsupported claim that they create a unified cache or guarantee instant actions. Navigation objects and dashboard actions can guide users to another sheet whether visible tabs are part of the design or not.

Embedded and published data sources

An embedded data source travels with a workbook and is managed in that workbook. It is practical for a self-contained analysis, but duplicated embedded definitions can drift across many workbooks. A published data source is a separately managed asset that multiple workbooks can connect to. Centralized calculations, metadata, extracts, and connection information can then be updated once for downstream consumers.

Publishing a data source requires a target project, permissions, authentication choices, and—when it is an extract—an appropriate refresh plan. Downstream authors need Connect permission. Replacing or overwriting a shared source can affect many workbooks, so perform impact review, preserve compatible field names and types, and test representative dependents.

Authorized Creator users can edit certain published data sources in the browser from the data-source page. The browser scratchpad supports metadata work such as renaming fields, creating folders and hierarchies, changing aliases, and creating calculations before publishing changes. Desktop workflows can also create a local copy or connect and publish changes when supported. There is no generic Save to All Connected Workbooks command inside one downstream workbook.

Authentication and refreshes

For a live connection, choose an authentication mode that meets the source's security and usability requirements. Prompting each viewer can preserve per-user database identity. Embedded credentials can support shared access but must be permitted and governed. OAuth may provide managed tokens for supported services.

An unattended extract refresh cannot stop to ask a person for a password. If the published connection requires interactive prompting and no usable stored credential or token is available, the background refresh fails. Validate scheduled refreshes with the server or cloud environment's actual network route. Tableau Bridge may be needed for Tableau Cloud to reach supported private-network data.

Publishing flows

Tableau Prep Builder flows can be published when the environment and licenses support them. A flow contains input, cleaning, transformation, and output steps; the .tfl or packaged .tflx definition is distinct from the output data. Published flows can be run manually or through supported scheduling capabilities. A flow output might write to a file, a database table, or a published data source depending on the configured connector and deployment. Certification is a separate governance action performed by an authorized user; publishing an output does not automatically certify it.

Downloads, exports, and sharing

Viewers can share a link to content they are allowed to see. Depending on site configuration and permissions, they may export an image, PDF, PowerPoint, crosstab, summary data, or underlying data, or download a workbook. These are separate capabilities. Granting View does not automatically mean a user may download full data or the workbook.

A custom view saves filter, sort, selection, and zoom state for the existing published view. It does not make a new workbook or alter the source data. Subscriptions deliver a view on a schedule or after a refresh when supported. Data-driven alerts notify recipients when a continuous measure crosses a condition. Select the feature that matches the request: link for access, export for a static artifact, custom view for saved state, subscription for recurring delivery, or alert for a threshold.

Revisions and rollback

Revision history can retain prior workbook and data-source revisions when enabled. Tableau Server uses a default maximum of 25 revisions unless an administrator changes it. Tableau Cloud retains up to 10 revisions. A revision restores content, not necessarily every external database state or credential. Confirm the platform, retention setting, and dependencies before relying on rollback.

Publication checklist

  1. Validate workbook calculations, filters, actions, device layouts, and accessibility.
  2. Choose embedded or published sources based on reuse and governance.
  3. Select the correct project and verify group permissions and tab semantics.
  4. Configure credentials appropriate for interactive views and unattended refreshes.
  5. Publish only intended sheets and supply useful descriptions and ownership.
  6. Test as a representative viewer, author, and refresh service.
  7. Confirm download, export, custom-view, subscription, and alert behavior matches policy.
  8. Record dependencies and monitor the first scheduled job.

Publishing is complete only when the hosted asset renders, refreshes, and enforces access as intended.

Test Your Knowledge

An author publishes a workbook whose views need different permissions. The project allows customizable permissions. Which publishing choice makes independent view permissions possible?

A
B
C
D
Test Your Knowledge

A data analyst publishes a workbook with a Hyper extract to Tableau Server and configures a scheduled extract refresh to execute every morning at 2:00 AM. During the publishing configuration, the analyst sets the Database Authentication option to 'Prompt User'. What occurs when the scheduled refresh runs at 2:00 AM?

A
B
C
D
Test Your Knowledge

Thirty workbooks use one published data source. An authorized Creator must update a shared calculation for all consumers. What is the governed approach?

A
B
C
D