Tableau Project Ownership & Security Permissions

Project Ownership

ITS provisions Top-Level Projects for each U-M School, College, or Unit. Every top-level project must have one designated owner who acts as the primary ITS contact.

Project Owners have the ability to: 

  • Manage permissions for each Project 
  • Create sub-projects
  • Assign one or more Administrators for each Project and sub-Project

Security, Permissions, and MCommunity Group Management

Access to Tableau Cloud is managed through MCommunity Groups. Individual U-M user accounts cannot be provisioned directly to Tableau Cloud. 

Mcommunity Setup & Provisioning

  1. Create an MCommunity Group
    Ensure your team or unit has an active MCommunity group containing the appropriate users.
  2. Submit a Sync Request
    Submit a ticket to the Tableau team to import and link your MCommunity group to Tableau Cloud.

MCommunity Group Syncing

  • MCommunity groups automatically synchronize with Tableau Cloud approximately every 15 minutes.
  • Nested Groups are imported
    Members of sub-groups will be added as part of the primary group. This also applies to sub-groups of sub-groups.
  • Expired Groups
    If an MCommunity group expires, it is immediately removed from Tableau Cloud.
  • Deprovisioning
    If a user is removed from all synced MCommunity groups, their site role reverts to an unlicensed status and they will not be able to log in.

MCommunity Permissions Best Practices

  • Create specific MCommunity groups only for those users who require dashboard access. Avoid using broad "all department staff" groups. 
  • Always grant project and workbook permissions to MCommunity groups, not individuals. While individual permissions can technically be assigned, any individual granted access to a workbook will be removed if their groups or group membership is removed.
  • Use multiple groups for tiered access. Maintain separate MCommunity groups if different workbooks or projects require different levels of security.