Assign role on sign in
With grant role on sign in, a licensed user just breezes straight through instead of hitting a denial of access on their first login.
- The grant-role-on-sign-in feature arrived in Tableau 2020.3 and requires the user to be a member of a group with the option enabled
- Enable it via a group's Details page by ticking 'grant role on sign in' and choosing the role (e.g. viewer or admin)
- An unlicensed user can sign in successfully but is denied access until assigned to a configured group; the role is then granted on their next login
- This removes the need for an admin to manually change roles through a support-desk process
- It works with Active Directory group syncing, so users can be assigned roles automatically on a schedule
Tableau can automatically grant a user's site role the moment they sign in, provided they're a member of a group configured for it — removing the need for an admin to manually assign roles via a support request.
Demonstrated on Tableau Online with a group set up to grant the viewer role on sign in, and an unlicensed user trying to log in for the first time.
- Create or open a group 0:22
Start from a group (new or existing) that you'll use to control role assignment.
- Unlicensed user signs in but is denied access 1:00
A user not yet in a role-granting group can authenticate successfully but still gets denied access — this isn't a login failure, just a missing licence/role.
- Add the user to the configured group 1:20
Assign the user to the group with the grant-role-on-sign-in setting. Their site role still shows as unlicensed immediately after this — the role isn't applied until their next sign in.
- Role is granted on next sign in 2:01
When the user logs in again, Tableau assigns the configured role automatically and lets them straight through, with no denial-of-access step.
- Works with Active Directory syncing 3:00
If you sync users to Active Directory groups on a schedule, this same mechanism can assign roles automatically as people join the relevant group — useful for onboarding, e.g. a new server admin gets the right role as soon as they're added and next sign in.
- The role isn't applied the instant you add someone to the group — the user's site role still shows unlicensed until they actually sign in again.
- This is one option among several ways to manage roles; you could still assign roles manually if you don't want automatic granting for a given group.
Reach for this when you're onboarding new users regularly and want their first login to work smoothly instead of hitting an access denial that then requires a manual admin fix.
How this Rollup was made provenance & method
A Rollup is drafted by AI from the video's transcript, then reviewed and edited by Tim. Everything used to produce this one is listed below — the model, the exact prompt, and the source video — so the process is transparent and reproducible.
- Transcription
- On-device — NVIDIA Parakeet v3 for recent videos, OpenAI Whisper large-v3 for earlier ones. The transcript never leaves the machine or gets published.
- Drafting
- Claude Sonnet 5 in the cloud, from that transcript.
- Prompt
- The exact Rollup prompt (v2) — the full system prompt, unedited.
- Source video
- Watch on YouTube
- Drafted
- 5 July 2026 at 09:38
- Reviewed & edited
- 5 July 2026 at 09:41 · by Tim Ngwena
Model + prompt + video is everything you'd need to recreate a Rollup like this yourself. The one thing we don't share is the transcript.
Rights. The video and its transcript are the property of TN Media Ltd. Unauthorised use or download is prohibited. © TN Media Ltd.