Following the carve-out from Siemens Energy, Trench Group faced a hard break: all analytics, reporting, and data processes – deeply embedded in the corporate group's landscape – had to be transferred into a fully independent environment within a very short timeframe. Zero downtime. No compromises on security. For 886 users. Worldwide.
What made this particularly high-stakes: Trench manufactures safety-critical high-voltage components – under strict compliance requirements, with globally distributed teams and ongoing reporting cycles that allowed no room for a single day of standstill.
Together with M2, this became a fully autonomous cloud analytics platform on AWS – secure, scalable, and independent of the former corporate group.
Mapping of all Tableau dashboards, data sources, Alteryx workflows, user groups, and security requirements within the Siemens environment. The result: a complete dependency graph defining migration sequence, risk clusters, and critical paths – the foundation for an uninterrupted separation.
Set-up of a scalable AWS landing zone with VPC design, network segmentation, and a centralized IAM concept. Zero-trust architecture with Azure Entra ID for SSO and role-based access control. The entire infrastructure was provisioned as Infrastructure-as-Code via Terraform – reproducible, versioned, and auditable.
Phase 1: Setup of a temporary Tableau Server environment on AWS for cleanup, validation, and testing of all dashboards and data sources.
Phase 2: Final cutover to Tableau Cloud, including permissions, roles, and data connections. In addition – beyond the original scope – development of an automated shop-floor dashboard solution with connected app authentication: real-time data on production monitors, with no login and no manual refresh required.
Setup of a 5-node Alteryx Server cluster with a MongoDB replica set and automated backups. SAP integration via Theobald Connectors. A CI/CD pipeline for zero-downtime deployments with minimal restore windows. Finally, intensive enablement: training on Tableau Cloud and Alteryx, introduction of the new permission structure, and joint QA of all reports – until Trench was fully able to operate autonomously.
Every segment now carries at least one concrete technical marker (dependency graph, VPC/Terraform, connected app auth, 5-node cluster/MongoDB). This positions M2 as a system architect, not a project coordinator. At the same time, it stays readable for decision-makers – the technology is embedded, not dominant.
At the heart of the project was the complete replacement of the former Siemens Energy infrastructure and the build-out of an independent, modern analytics environment for Trench Group – under one clear premise: ongoing operations must never be disrupted, at any point.
Within three months, M2 migrated all reporting and analytics processes to a new cloud architecture. Throughout the entire transition, all 886 users continued working without interruption – no dashboard offline, no reporting cycle delayed.
The new environment makes Trench independent of its former structures. Data pipelines, reporting precesses, and governance are clearly structured, automated, and implemented in full compliance with security requirements. At the same time, intensive enablement empowered the Trench team to operate the new infrastructure independently, without external dependencies.
Decisive for the future: the platform is built for growth. New locations, teams, and data sources can be integrated at any time – Trench can scale its analytics landscape by more than 300%, without any infrastructure rebuild.
„In just three months, we managed to build a modern analytics landscape – secure, high-performing, and without any interruption to ongoing reporting.“
Fabrizio Negri
Senior Vice President, IT
FAQ: Frequently Asked Questions about Analytics Migration and Carve-out Projects
The key is a complete inventory before the first migration step. All dashboards, data sources, ETL processes, user groups, and security requirements must be mapped out and represented in a dependancy graph. This produces a carve-out blueprint that defines migration sequence, risk clusters, and critical paths. Without this groundwork, dependencies cannot be controlled – and every uncontrolled dependency is a potential point of failure in ongoing reporting operations.
A two-stage Tableau migration strategy has proven effective: first, a temporary Tableau Server environment is set up, in which all dashboards are cleaned up, data sources validated, and tested against the new cloud infrastructure. Only after successful quality assurance does the final cutover to Tableau Cloud follow – including user permissions, roles, and data connections. The key lies in a clean separation of staging and production environments, so that no gap ever emerges in business reporting.
Companies with sensitive operational, production, or engineering data need an architecture that verifies every connection and controls every access – without disrupting day-to-day work. In practice, this means: a zero-trust architecture on AWS, identity and access management via Azure Entra ID with single sign-on and role-based access control, network segmentation through VPC design, and infrastructure-as-code via Terraform. This way, every configuration is reproducible, versioned, and auditable for compliance.
Through consistently cloud-native architecture design. A good AWS target architecture makes it possible to integrate new locations, teams, data sources, and dashboards at any time – without hardware expansion and without rebuild phases. What matters is modular infrastructure, automated deployments via CI/CD pipelines, zero-downtime backup strategies, and a clear separation of compute, storage, and visualization layers. Implemented correctly, growth rates of over 300% are realistic without any infrastructure overhaul.
That depends on scope and complexity. With a structured approach, even extensive migrations – several hundred users, diverse SAP and cloud data sources, complex Alteryx workflows – are achievable in three to six months. This requires a clearly defined migration blueprint, parallel work streams, and a project team proficient in both the source and target architecture on AWS. The time sinks are almost never the technical migration itself, but rather unresolved dependencies and a lack of stakeholder alignment.
Through enablement built in from day one – not tacked on afterward. This includes structured training for Tableau Cloud and Alteryx Server, the introduction of new role and permission structures, and joint quality checks of all reports and data pipelines. The goal is always full data autonomy: a good migration project ends with the client no longer needing the service provider.