Home
Methodology / version 1.3

What we know.
What we do not claim.

The health check combines a workspace-scoped metadata assessment with a separately defined expert review. Every conclusion is bounded by the assets, permissions and evidence available during the engagement.

The automated sample uses synthetic data. Paid delivery adds source-labelled expert observations and a consultant-written remediation backlog after human validation.

Observed, not assumed

A finding must trace to returned metadata or documented expert-review evidence. No evidence means unknown, not healthy.

Proportionate scoring

Related controls are grouped into risk families so one underlying condition does not create several full deductions.

Source-labelled conclusions

Automated findings and manual professional observations are labelled separately in the working papers and the report.

Minimum necessary data

The default path uses metadata, sanitized review artifacts and a local-first workflow. No AI is involved.

01 / Scope and coverage

Coverage is stated before conclusions are drawn.

Workspace metadata is captured either by the customer-side scanner, which uses ordinary Power BI workspace APIs, or in a guided screen-share that follows the same checklist. “In scope” means you selected that workspace and the evidence needed for a control was actually seen.

Evidence layerCurrent coverageMethodExplicit limit
Workspace estateNamed authorized workspaces, reports and semantic modelsScanner or guided captureNo My Workspace or unauthorized workspace discovery
AccessWorkspace users, groups, apps and rolesScanner or guided captureNot an identity-governance or sharing-link audit
RefreshRecent model refresh attempts and durationScanner or guided captureUnavailable history is not treated as healthy
Model designUp to five agreed priority modelsEight static TMDL checks plus expert review of approved artifactsStatic patterns only; no query execution or exhaustive DAX verification
Report experienceAgreed priority reports paired with reviewed modelsExpert review of approved evidenceNot an exhaustive review of every page, visual or business result
02 / Deterministic controls

Ten estate controls.
Eight model checks.

Rules produce findings from normalized metadata and from the model definition files you select. No AI creates findings, changes severity or changes the score.

01

Refresh continuity

Consecutive failures; latest refresh failed

Identify observed availability risk without counting the same refresh condition twice.

02

Refresh performance

Latest duration versus recent successful baseline

Surface a material duration anomaly when sufficient comparable history exists.

03

Access exposure

Administrator count; administrator ratio

Flag elevated workspace access for human least-privilege review.

04

Artifact hygiene

Similar report names; version markers; model without a report in scope

Identify cleanup candidates while preserving the need for owner confirmation.

05

Estate structure

Empty workspace; high report count

Highlight workspace lifecycle and maintainability questions.

06

Model design (PBIP/TMDL)

Bi-directional and many-to-many relationships; auto date/time tables; measures without format; implicit measures; visible key columns; unsafe division; floating-point columns

Give the expert review a consistent starting list. These are static review prompts, not a tenant score.

03 / Scoring and evidence

A triage signal,
not a certificate.

100-point starting point

Observed findings create defined deductions. The score helps order attention; it does not prove compliance or future reliability.

Family-level deductions

Closely related rules share a risk family so repeated symptoms of one condition do not multiply the full deduction.

Private source evidence

You review source details in the local scan. The shared summary deliberately omits names, IDs and raw evidence.

Unknown remains unknown

A failed or unseen collection stays an evidence gap, never a passing control. Model checks never contribute to the score.

Paid-delivery backlog: the consultant starts from the evidence you approved, validates each finding and records its evidence source, impact, owner, timing, acceptance test and status by hand.
04 / Handling and review

Evidence travels the shortest path.

  1. 01AuthorizeYou sign in with Microsoft on your own computer, or share your screen in the Power BI service. No password or client secret is ever given to the consultant.
  2. 02CaptureThe scanner saves a scoped snapshot on your computer; in a guided session the consultant notes control outcomes and reads them back before the call ends.
  3. 03ReviewYou choose whether to export a redacted summary. The consultant validates findings and requests agreed additional evidence only if needed.
  4. 04DeliverThe deliverable states scope, capture route, unavailable evidence, assumptions and findings, then adds the completed backlog and prioritized plan.
  5. 05CloseYou delete the raw local snapshot under your own retention policy. Anything deliberately shared for the review follows an agreed deletion date.
The browser application can be run locally or on an approved host. It is not a multi-user SaaS with customer accounts or a tenant-wide monitoring service.
05 / Exclusions

What this health check does not prove.

A complete inventory of the Power BI tenant
Formal regulatory, legal or security compliance
Correctness of every KPI or underlying business record
Performance under production load or capacity sizing
Absence of access paths outside returned workspace roles
Exhaustive verification of DAX, M or report visuals
That a cleanup candidate is safe to delete without owner review
Implementation of fixes beyond the included same-scope re-check
See both layers in context

Review a synthetic sample.

The sample deliverable shows the complete paid format; the automated sample shows only the estate-metadata layer. Neither is generated from a customer scan.