BI Strategy and Reporting
Written By: Sajagan Thirugnanam
Last Updated on September 23, 2026
A data governance strategy in Power BI and Microsoft Fabric works when the rules are enforced by the product, not when they are written down. Six pieces do the enforcing: who can open a workspace, whose rows a semantic model filters, which content carries a sensitivity label, which reports are marked trustworthy, whether a report's data can be traced back to its source, and whether anyone is checking the logs. Set up each one, and the strategy holds even when nobody is reminding people to follow a policy document.
This post covers the mechanics. For where governance sits among the other layers of a data strategy, such as sourcing, platform and the semantic layer, see our guide to building a data strategy framework.
Step 1: Set the workspace as the access boundary
A Fabric workspace is a separately securable container. Everyone who can open it shares access to the semantic models, reports and other items inside it, and everyone who cannot open it sees nothing. Four roles control that access:
Admin can update or delete the workspace and add or remove anyone, including other admins.
Member can add people with lower permissions and edit content, but cannot remove anyone from a role.
Contributor can create and modify content, but cannot manage who else has access.
Viewer has read-only access to workspace content.
Roles can be assigned to a single person or to a security group, a Microsoft 365 group or a distribution list. If you nest groups and assign a role to the outer group, everyone inside inherits it. Assigning roles to groups instead of individual people means adding or removing one person from that group updates their access everywhere the group is used, instead of editing every workspace by hand. For the full breakdown of what each role can and cannot do, see our guide to Power BI workspace roles.
Step 2: Narrow access below the workspace with row-level security
A workspace role controls the whole workspace. Row-level security (RLS) controls which rows inside one semantic model a person sees, and the two interact in a way worth planning for directly: RLS in Power BI only applies to people with the Viewer role in that workspace. Admins, Members and Contributors have edit permission on the semantic model, so RLS does not filter their view. If a governance plan calls for RLS to apply to someone, that person can only be given the Viewer role in that workspace.
A dynamic RLS role uses a DAX filter expression that looks up the signed-in user against a mapping table:
Two people with Viewer access to the same report see different rows, filtered by their own department, without a separate report built for each of them. Define the roles in Power BI Desktop, publish, then add members to each role in the Power BI service. Our guide to Power BI row-level security covers static roles, testing a role before publishing, and how RLS behaves with DirectQuery and Direct Lake models.
Step 3: Classify content with sensitivity labels
Sensitivity labels come from Microsoft Purview Information Protection, the same labeling system used across Office. They can be applied to semantic models, reports, dashboards, dataflows and paginated reports, in Power BI Desktop or in the Power BI service. They cannot be applied to workbooks.
Two things about how they behave are easy to assume wrong:
A label does not restrict access inside the Power BI service. Access there is controlled entirely by workspace and item permissions. What a label controls is what happens when the data leaves Power BI: export to Excel, PowerPoint or PDF, download to .pbix, and Analyze in Excel all carry the label's encryption settings with them, so only people with sufficient usage rights can open the exported file.
Labels travel on their own once applied. A new report built on a labeled semantic model automatically inherits that label. A label applied to a semantic model or report can also flow downstream to content built on top of it. When a labeled semantic model is opened in Excel through a live connection, the label carries over there too, and an Excel file never gets downgraded to a less restrictive label than the one already on it.
Sensitivity labels are created and managed in the Microsoft Purview portal, not in Power BI itself, and a tenant needs the right license enabled before they show up as an option.
Step 4: Endorse content so people know what to trust
Endorsement is how a governed content catalog tells people which report to open first. Fabric has two core levels that apply to almost every item type except Power BI dashboards, plus a separate badge for a different purpose:
Promoted content is highlighted by whoever made it, or anyone with write permission on it, as good enough to share. It signals "someone stands behind this," not "this has been reviewed."
Certified content has been reviewed against the organization's own quality standard by a reviewer the Fabric administrator has specifically authorized. It signals "this has been checked," and item owners who are not authorized reviewers have to request certification rather than apply it themselves.
A third badge, Master data, marks an item as the organization's single source of truth for something like a customer list or a product code table, and is also restricted to authorized reviewers. Endorsed items are labeled wherever people browse for content, including in search results and in Excel's Get Data experience, and certified and promoted items are prioritized ahead of unendorsed ones.
Step 5: Make the data's path traceable with lineage view
Every Fabric workspace has a lineage view built in, showing every item in the workspace, how they connect to each other, and the external data sources feeding the semantic models and dataflows one level upstream. Open it from the workspace toolbar, from an item's options menu, or from the item's own details page.
Anyone with a role in the workspace can open lineage view, but a Viewer will not see the data source cards, only the items and connections between them. Lineage view shows upstream connections outside the workspace, but not downstream ones in other workspaces; to see what depends on an item across workspace boundaries, Fabric's impact analysis view covers that instead. When a report stops matching what someone expects, lineage view is where to check whether it is reading from the data source it should be.
Step 6: Review the logs, do not assume the rules held
Every time a sensitivity label is applied, changed or removed, Power BI records it in the audit log, alongside activity such as who viewed a labeled report and when. The Power BI admin portal also has a protection metrics report that gives a tenant-wide view of where sensitive data actually is. Neither of these runs itself. Set a cadence for someone to open both and check that labels landed where they were supposed to and that endorsement badges still match reality, rather than assuming the rules from steps 1 through 5 are still holding.
FAQs
What are the key components of a data governance strategy in Power BI and Fabric?
Workspace roles decide who can open a workspace. Row-level security narrows what a Viewer sees inside a semantic model. Sensitivity labels classify content and protect it once it leaves Power BI. Endorsement tells people which content to trust, and lineage view traces a report back to its source. Each one is enforced by the product, not a rule people have to remember.
How often should a data governance strategy be reviewed?
Review it whenever a new workspace or capacity is created, and whenever a sensitivity label policy changes. Beyond that, set a fixed cadence, such as once a quarter, and check the Power BI admin portal's protection metrics report and audit log rather than relying on memory of what was configured.
What role does technology play in data governance?
It does the enforcing. Workspace roles decide who can open a workspace regardless of what a policy document says. Sensitivity labels apply their protection automatically the moment content leaves Power BI through a supported export path. Endorsement decides what shows up first when someone searches for a report. None of these depend on a person remembering to follow a written rule.
Sources
Roles in workspaces in Microsoft Fabric - Microsoft Learn
Row-level security (RLS) with Power BI - Microsoft Learn
Sensitivity labels in Power BI - Microsoft Purview Information Protection - Microsoft Learn
Endorse Fabric and Power BI items - Microsoft Learn
Lineage in Fabric - Microsoft Learn
Related to BI Strategy and Reporting