The Power BI Fellowship

Governance Track

Governance done well is invisible: people find the trusted model first, sensitive data stays where it should, and unused content quietly disappears. Done badly it's a gate everyone routes around. This track is about the light-touch version that works, practised on Northwind's tenant from Sprint 10.

Before you start A Power BI or Fabric trial tenant helps for the Service steps, but every assignment has evidence files (data/experience/s10 and data/tracks/automation) so you can do the analysis without one.

Workspaces, domains, ownership and endorsement

Why it matters
Workspace structure and endorsement decide where people look for data and which numbers they trust. Without them, every team builds its own copy.
Typical production failure
Nineteen models, five customer tables and four names for revenue (Sprint 10), because nothing tells users which one is official.
When to use it
Domain workspaces with named owners, separate Dev/Test/Prod for content many people rely on, promotion for good team content, certification with written criteria for company-wide models.
When not to
Certifying content no one owns, or a review process so heavy that teams stop asking.

Assignments

A workspace and domain plan for Northwind

B · Objective 40 min · uses data/experience/s10/workspaces.csv

Using the Sprint 10 inventory, propose how workspaces should be organised: names, domains, who owns them, which ones get Dev/Test/Prod, and what happens to personal and test workspaces.

Requirements
  • A naming convention.
  • A domain per business area with an owner.
  • Workspace roles: who is Admin, Member, Contributor, Viewer, and why consumers use apps instead of workspace roles.
  • Which workspaces need deployment pipelines.
Expected result: Domain workspaces (Sales, Finance, Operations, Marketing, HR, Supply Chain) with named owners and a convention like "<Domain> – <Purpose> [Dev|Test]"; at most two or three Admins per workspace; consumers through apps or audiences; pipelines for workspaces holding certified models; personal and test workspaces kept out of production use.

Write the certification criteria

C · Problem 30 min · uses —

Elena asks for the criteria a semantic model must meet before it's certified, short enough that people read it, strict enough that "certified" means something.

Work out
  • Ownership, documentation, testing, security, refresh, performance and change control.
  • Who can certify and how certification is reviewed or removed.
What good looks like: One page: named business and technical owner; KPI dictionary and measure descriptions; data and model tests passing; RLS test matrix where relevant; refresh monitored with team alerts; meets the performance budget; changes through Git and a pipeline; reviewed yearly; certification removed when criteria lapse. Only a small, named group can certify.

Promoted or certified?

B · Objective 15 min · uses —

Classify five items: endorse as Promoted, Certified, or neither. Justify each.

Requirements
  • The shared sales model with an owner, tests and a KPI dictionary.
  • Marketing's campaign model, used by its own team, maintained but undocumented.
  • A copy of the sales model someone made to add one measure.
  • Finance's board pack model, owned by the CFO's team, reconciled to the ledger monthly.
  • A one-off analysis for a single meeting.
Expected result: Certified: shared sales model, Finance board pack. Promoted: Marketing's model (useful, maintained, not company-wide). Neither: the copy (merge the measure into the shared model and retire it) and the one-off (personal workspace, then delete).

Interview questions

  • Promoted vs certified?
  • What are Fabric domains for?
  • Why shouldn't report consumers be workspace Viewers on a development workspace?
  • What makes governance actually work?

Assessment

Who can certify a semantic model?

  • Any workspace member
  • Only users authorised by the Fabric administrator for certification
  • Only the model owner
  • Anyone with Build permission

A team copies the certified sales model to add one measure. Best response:

  • Certify the copy too
  • Add the measure to the certified model (or a composite on top) and retire the copy
  • Ignore it
  • Delete both

In a trial tenant, promote one model, request certification for another, and find both in the OneLake catalog with the endorsement filter.

Settings → Endorsement and discovery on the item.

Sensitivity labels, OLS, export controls and tenant settings

Data: DimEmployee
Why it matters
Data leaves Power BI through exports, Excel, emails and PDFs. Labels and settings decide whether protection travels with it.
Typical production failure
A payroll export to Excel is emailed outside the company; nothing marked it as confidential and nothing stopped the export.
When to use it
Sensitivity labels on sensitive models and reports (inherited downstream and into exports), OLS for columns some users must not see, export settings per report, tenant settings restricted to security groups, least privilege everywhere.
When not to
Turning off export for everyone: people screenshot or copy instead, and you lose the audit trail.

Assignments

Protect the payroll columns

A · Guided 30 min · uses DimEmployee (course dataset)
  1. In the starter model, create a role "Managers" with RLS on region and a role "Analysts" with OLS on DimEmployee[Salary] (metadata permission None), using Tabular Editor or the TMDL view.
  2. View as Analysts: build a table with EmployeeName and Salary. It errors; remove Salary and it works.
  3. View as Managers: Salary visible, rows limited to the region.
  4. Apply a sensitivity label (if your tenant has labels) and export to Excel: check the label travels with the file.
Expected result: Analysts can't see that the Salary column exists; Managers see salaries for their region only; the exported file carries the label.

Decide the export and sharing settings

C · Problem 30 min · uses —

Ava (Compliance) wants all export disabled tenant-wide after the Sprint 03 incident. Sales says they need Excel every day. Propose settings that protect sensitive data without blocking everyone.

Work out
  • Which tenant settings you change and for which security groups.
  • Report-level export settings for sensitive reports.
  • What labels and audit provide that a blanket ban doesn't.
What good looks like: Keep export for most users, restricted by security groups in tenant settings; disable underlying-data export on sensitive reports; mandatory labels on sensitive models with protection that follows exports; audit logs for exports reviewed by Compliance. A blanket ban drives screenshots and copies, which nobody can audit.

Least privilege for a new analyst

B · Objective 15 min · uses —

A new Finance analyst needs to build reports on the certified board pack model, but not change the model or see payroll. What access do they get?

Requirements
  • Workspace role or item permission.
  • Build permission and why.
  • Which security roles in the model they belong to.
Expected result: No role in the model's workspace; Build permission on the semantic model (to create reports on it); membership of the Finance RLS/OLS role that excludes payroll; their own workspace (or a team workspace) for their reports.

Interview questions

  • What does a sensitivity label do in Power BI?
  • OLS vs hiding a column?
  • Why restrict tenant settings to security groups?
  • What is least privilege in Power BI terms?

Assessment

A report built on a labelled "Confidential" model is exported to Excel. With label inheritance:

  • The file has no label
  • The file carries the Confidential label
  • The export fails
  • Only the first sheet is labelled

An analyst should build reports on a model without seeing its workspace. Give them:

  • Admin on the workspace
  • Build permission on the semantic model
  • Contributor on the workspace
  • Nothing; it isn't possible

List the five tenant settings you'd review first in a new tenant, and the group each should be limited to.

Export to Excel/CSV, publish to web, external sharing, service principals calling APIs, creating workspaces.

Monitoring, lineage, usage and retirement

Data: ApiReports ApiViews
Why it matters
Content accumulates. Usage and lineage tell you what to invest in, what to fix first and what to retire safely.
Typical production failure
A "clean-up" deletes a model with no report views; the monthly commission paginated report that depended on it fails on payroll day.
When to use it
Usage metrics and activity events for what's used, lineage and impact analysis for what depends on what, capacity metrics for cost, and a retirement process with notice and a read-only period.
When not to
Deleting based on view counts alone.

Assignments

Find retirement candidates, safely

B · Objective 35 min · uses reports.json, activity_views.json

From the mock activity events, list the reports nobody viewed in 90 days and the most-viewed one, then say what you must check before retiring any of them.

Requirements
  • Unused reports from the activity data.
  • The most-viewed report and its views.
  • The checks before retirement (lineage, subscriptions, paginated reports, Excel connections, owners).
Expected result: 7 of 18 reports had no views in 90 days; the most viewed is "Finance Detail Overview" with 60 views. Before retiring: impact analysis, subscriptions, dashboard tiles, Analyze in Excel connections, owner contact, then read-only for 30 days.

What should a BI monitoring page show?

C · Problem 30 min · uses —

Design one page Elena can check every Monday that shows the health of the estate. Choose at most eight numbers and justify each.

Work out
  • Refresh, usage, capacity, ownership and quality signals.
  • Which numbers have thresholds and who acts on them.
What good looks like: For example: failed refreshes (7 days), certified-model refresh duration trend, capacity peak utilisation and throttling, views on certified vs uncertified content, items without owner, retirement candidates, data-quality test failures, open incidents. Each with an owner and a threshold.

Run a retirement

B · Objective 20 min · uses data/experience/d05

Write the retirement runbook your team will use, based on the Regional Sales Weekly drill (D05).

Requirements
  • Steps with timing.
  • Who's notified at each step.
  • What makes you stop and roll back.
Expected result: Check dependencies → notify owner and recent viewers → banner and move subscriptions/tiles → read-only 30 days → archive → delete after 90 days; stop if a dependency or an objection appears; restore from archive if needed.

Interview questions

  • What's the difference between usage metrics and activity events?
  • What does impact analysis show?
  • Why can a model with zero report views still be important?
  • What does the Capacity Metrics app tell you?

Assessment

A model has no report views in 90 days. Before deleting it you should check:

  • Nothing
  • Lineage/impact analysis, subscriptions, paginated reports and Excel connections, and ask the owner
  • Only its size
  • The tenant settings

Which source tells you who exported data to Excel last week across the tenant?

  • Report usage metrics
  • Activity events / audit log
  • Refresh history
  • Lineage view

Build the Monday health page from your design using the inventory and refresh data from the automation track.

Load inventory.csv and the refresh history into a small model; one card per signal with a threshold-based colour.