The correct security mechanism is the Einstein Trust Layer's PII masking capability. Salesforce guidance for AI-assisted calculated-field creation states that the agent may use information from the semantic model, including its schema and metadata, and that personally identifiable information is masked by the Einstein Trust Layer before information is sent to the LLM.
This allows Tableau Next's generative functionality to receive the semantic context required to construct useful calculated fields while applying Salesforce's enterprise AI security controls.
Option A describes a whole-model encryption/decryption workflow that is not the documented Tableau Next processing model. Option C is also incorrect because the system does not simply prohibit every field that could potentially contain PII. Instead, the Trust Layer applies masking and other controls to protect sensitive information while retaining useful analytical context.
More broadly, Salesforce states that Tableau Agent and Agentforce inherit the Einstein Trust Layer's security, governance, and trust mechanisms, including protections designed to prevent customer data from being retained by external LLMs for model training.
References/Topics: Agentic Experiences - > Einstein Trust Layer - > PII Masking - > Generative AI Calculated Fields.
===========================================================================
Submit