Skip to main content

Microsoft Fabric Governance Assessment — OneLake, domains, workspaces, semantic models, capacity cost and Purview

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

EPC Group's Microsoft Fabric governance assessment scores your Fabric estate across seven areas — OneLake and the lakehouse, domains and workspaces, semantic models and certification, capacity and cost, Purview and data protection, access and sharing, operating model and ownership — on a 0–3 rubric with the evidence behind each score, and delivers a ranked findings register, the target architecture and domain model, a capacity and cost plan against Microsoft list pricing, a Purview and access remediation plan and an operating model. Four weeks, six deliverables, a senior architect end to end. 500+ Fabric implementations and 1,500+ Power BI deployments behind the method. Fixed-scope, priced after a scoping call.

Key Facts

  • Seven areas scored 0–3 with evidence: OneLake, domains and workspaces, semantic models, capacity and cost, Purview, access and sharing, operating model
  • Six deliverables: scorecard, ranked findings register, target architecture and domain model, capacity and cost plan, Purview and access remediation plan, operating model and roadmap
  • Capacity plan built against Microsoft list pricing and your own capacity metrics — no EPC rates
  • Semantic-model certification treated as AI readiness: the models Copilot and Fabric data agents answer from
  • Four weeks single-tenant; six for multi-capacity or multi-geo estates, scoped up front
  • 500+ Fabric implementations · 1,500+ Power BI deployments · Microsoft consulting since 1997
  • Sample deliverable set walked through, redacted, on the scoping call; contracted records in the Evidence Center

Why Fabric estates need governing after the fact

Microsoft Fabric makes it easy to start: a capacity, a workspace, a lakehouse, a semantic model, a report — in an afternoon. Twelve months later the same ease has produced dozens of workspaces with no owner, several copies of the same table in different lakehouses, semantic models the business trusts and models it does not with no way to tell them apart, a capacity that throttles at month-end and a renewal nobody can defend, and sensitivity labels that stop at the report because nobody configured inheritance from the item. Then Copilot or a Fabric data agent is pointed at the estate, and every one of those gaps becomes an answer a user believes.

The assessment measures the estate as it is, in seven areas, with evidence; ranks what to fix; designs what to fix it against; and prices the capacity honestly against Microsoft list pricing. It is the analytics-platform application of the same discipline as the Copilot readiness assessment — surfaces 5 and 8 of TAR-8, in depth.

The seven areas the assessment scores

1

OneLake and the lakehouse estate

What lives in OneLake, who owns it, how it is layered (bronze, silver, gold or their equivalents), where shortcuts and mirroring reach outside the tenant, and whether the estate has a single source of truth or six copies of the same table.

2

Domains and workspaces

The domain model against the organization; workspace naming, ownership, roles and lifecycle; the split between development, test and production; Git integration and deployment pipelines; orphaned and personal workspaces carrying production data.

3

Semantic models and certification

Which models are certified, promoted or neither; row-level and object-level security; the endorsement process; Direct Lake versus import versus DirectQuery decisions; and whether the models Copilot and Fabric data agents answer from are the ones the business trusts.

4

Capacity and cost

F-SKU sizing against actual utilization, throttling and smoothing behavior, capacity-per-domain versus shared, pause and scale patterns, and the workloads that consume the most capacity units for the least value. The cost plan is written against Microsoft list pricing.

5

Purview and data protection

Sensitivity labels on Fabric items and their inheritance into Power BI and exports, DLP for Fabric, the Purview Data Map and catalog coverage, data-lineage completeness, and whether the labels survive the path from lakehouse to report to Copilot answer.

6

Access, sharing and external exposure

Item-level and workspace-level permissions, sharing links, external users, service principals and their scopes, and the audit-log coverage that lets you answer who read what.

7

Operating model and ownership

Who owns the platform, the domains, the certified models and the capacity budget; the change and release process; the monitoring in place; and the governance board that decides. Surface 5 and surface 8 of TAR-8, applied to Fabric.

Scoring: 0 — no control; 1 — the control exists but is not applied to the production estate; 2 — applied, with gaps the register names; 3 — applied, evidenced and owned.

The six deliverables

1

Fabric governance scorecard

The seven areas scored 0–3 with the evidence behind each score — the setting, the admin-portal export, the capacity metrics report — so the score can be re-derived and re-scored next quarter.

2

Findings register, ranked

Every finding classified as a blocker (exposure, cost or trust issues to close before the platform grows), a maturity gap (close in the first quarter) or an observation, with the owning team and the Fabric, Purview or Power BI control that closes it.

3

Target architecture and domain model

The domain and workspace model, the lakehouse layering standard, the shortcut and mirroring policy, the environment and deployment-pipeline design, and the semantic-model certification standard — written as the standards your platform team will adopt.

4

Capacity and cost plan

F-SKU right-sizing with the utilization evidence, capacity allocation by domain, pause and scale schedule where workloads allow it, and the cost model against Microsoft list pricing for the next four quarters.

5

Purview and access remediation plan

Label taxonomy and inheritance rules for Fabric items, DLP policies, catalog and lineage coverage targets, permission and sharing remediation waves, and the audit configuration — sequenced ahead of any Copilot or data-agent enablement on the estate.

6

Operating model and roadmap

Ownership, the certification and release process, monitoring, the governance board and its cadence, and the order of remediation — delivered with a 90-minute executive readout and the sample deliverable set redacted for comparison.

The sample deliverable

Before you commit, you see what you will receive. On the scoping call the architect walks through a real deliverable set with the client, workspace names, capacity identifiers and figures redacted: the seven-area scorecard with its evidence column; a findings register showing classification, owner and closing control; the domain and workspace model diagram; the capacity utilization chart with the right-sizing recommendation and the list-price cost model; the label-inheritance rules page; and the first phase of the roadmap. The numbers in it belong to that client and are not published — what you are judging is the depth and the shape of the work.

Participants, duration, prerequisites

Who takes part

The Fabric or Power BI administrator (admin-portal read access and the capacity metrics app); the data-platform lead; the security or compliance lead for Purview decisions; the finance owner of the capacity budget; two to four domain owners for workshops. EPC Group: one senior architect who scopes, leads and presents.

How long it takes

Four weeks single-tenant — inventory and OneLake, domains, workspaces; then semantic models, capacity and Purview; then the register, architecture and cost plan; then validation and the executive readout. Multi-capacity or multi-geo estates are scoped to six weeks, in writing, before work starts.

What we need before day one

A named sponsor; Fabric administrator read access and the capacity metrics app; Purview read scopes; workspace, item and permission exports where the tenant allows; the capacity invoices or Azure cost view for Fabric; workshop time with the domain owners. No capacity change is required to be assessed.

Why EPC Group

Frequently Asked Questions

What is the Microsoft Fabric governance assessment?

A fixed-scope engagement in which EPC Group scores your Microsoft Fabric estate across seven areas — OneLake and the lakehouse, domains and workspaces, semantic models and certification, capacity and cost, Purview and data protection, access and sharing, operating model and ownership — on a 0–3 rubric with the evidence behind each score, then delivers a ranked findings register, the target architecture and domain model, a capacity and cost plan against Microsoft list pricing, a Purview and access remediation plan and an operating model. EPC Group has delivered 500+ Microsoft Fabric implementations and 1,500+ Power BI deployments.

Who is it for?

Organizations that adopted Fabric quickly — a trial capacity that became production, workspaces created by whoever needed one, semantic models nobody certified — and now face a renewal, a cost question, a Copilot or data-agent rollout that will answer from those models, or an audit that asks who can read what. Also organizations about to migrate a Power BI Premium estate to Fabric who want the governance designed before the capacity is bought.

What does the sample deliverable look like?

A real deliverable set with the client, workspace names, capacity identifiers and figures redacted: the seven-area scorecard with its evidence column, a findings register with classification, owner and closing control, the domain and workspace model diagram, the capacity utilization chart with the right-sizing recommendation, the label-inheritance rules page and the first phase of the roadmap. It is walked through on the scoping call so you can see the depth before you commit; the underlying numbers belong to that client and are not published.

How does the capacity and cost work relate to Microsoft pricing?

The cost plan is built against Microsoft list pricing for Fabric capacity and Power BI licensing and against your capacity metrics — utilization, throttling, smoothing, the workloads consuming the most capacity units. It recommends the F-SKU, the allocation by domain and the pause and scale schedule the workloads allow. EPC Group publishes no rates of its own; the engagement is fixed-scope and priced after a scoping call.

Why do semantic models get so much attention?

Because they are what the business, Copilot and Fabric data agents answer from. An uncertified model with the wrong row-level security is a governance failure that looks like an AI failure. The assessment inventories every model, checks its security and endorsement, decides the Direct Lake, import or DirectQuery question on evidence, and sets the certification standard the platform team will run — surface 5 of the TAR-8 tenant AI readiness standard, applied in depth.

How does Purview fit into Fabric governance?

Sensitivity labels applied to Fabric items inherit into Power BI reports and exports and, when configured, constrain what Copilot surfaces; DLP for Fabric catches sensitive data in lakehouses; the Purview Data Map and catalog give lineage and discovery. The assessment checks coverage and inheritance end to end — lakehouse to model to report to answer — and the remediation plan sequences the labeling ahead of any AI enablement on the estate.

How long does it take, and who takes part?

Four weeks for a single-tenant estate, six where Fabric spans several capacities or geographies (scoped up front). From your side: the Fabric or Power BI administrator (read access to the admin portal and capacity metrics), the data-platform lead, the security or compliance lead for Purview decisions, the finance owner of the capacity budget, and two to four domain owners for workshops. From EPC Group: a senior architect who leads the assessment end to end and presents the readout.

What are the prerequisites?

A named sponsor; Fabric administrator read access and the capacity metrics app; the Purview portal read scopes; an export of workspaces, items and permissions where the tenant allows it; the current capacity invoices or the Azure cost view for Fabric; and workshop time with the domain owners. No capacity change is required to be assessed.

What happens after the assessment?

Your platform team adopts the standards and executes the remediation waves; EPC Group implements the target architecture and the migration to it as a fixed-scope implementation; or the Power BI and Fabric governance Center of Excellence engagement stands up the operating model with your team and runs it until it is self-sustaining. None is required; the deliverables are complete on their own.

How is it priced?

Fixed-scope, priced after a scoping call that confirms the number of capacities, workspaces and domains in scope; there is no rate card. Microsoft Fabric capacity and Power BI licensing are quoted at Microsoft list price. Contracted engagement records for comparable analytics governance work are published, redacted, in the EPC Group Evidence Center.

Related EPC Group services and references

Book the scoping call

Thirty minutes with the architect who will lead the assessment. Bring your capacity metrics; you leave with the scope, the participant list, the access request and the redacted sample walkthrough.

AI assistant — not human