For Microsoft Fabric and Power BI

Your whole Fabric estate, mapped.

Fabriscope scans every lakehouse, warehouse, notebook, pipeline, dataflow, semantic model and report in your tenant. It builds full data lineage — showing how every table got created and which notebook or pipeline produced it — and it resolves access, telling you exactly who can see each report and who can reach the raw data underneath.

Metadata only Not a single row of your data is ever read.

Lineage: a SQL Server table and a SharePoint workbook flow through lakehouse tables into a semantic model and a Power BI report. SALESLINE sql-d365-prod fx_rates.xlsx SharePoint salesline lh_bronze.d365 fx_rates lh_silver.ref fact_sales lh_gold.dbo Sales Model Direct Lake Revenue by region · bar

One scan reads the whole estate.

  • Lakehouse and warehouse tables · views
  • Notebooks and lake views %%sql · PySpark
  • Pipelines Copy · Notebook · Invoke
  • Dataflows Gen2 M
  • Warehouse T-SQL · query history
  • Eventstreams and mirroring
  • Semantic models and reports TMDL · PBIR
  • Delta logs, access, the audit log

Lineage and documentation

Fabriscope Data Catalog

Finds what writes every table
The notebook, pipeline, dataflow or eventstream — down to the exact cell or query.
Draws lineage end to end
From source systems through lakehouses and warehouses to semantic models and Power BI reports, across workspaces.
Explains tables and views
The SQL or PySpark behind each one, its schema, last write, rows and size.
Lets your team document it
Table and column descriptions written in place, with who edited them and when.
Shows who can read each table
Workspace roles, OneLake roles, and indirectly through semantic models.
Shows what runs it
Which pipeline triggers a notebook, and how its last run went.
Flags what needs attention
Stale tables, undocumented tables, and personal data exposed widely.
Never pretends
Every link is labelled declared, parsed or inferred; what it couldn't read is listed, not hidden.

Access and usage

Fabriscope Report Audience

Who can open each report
Every person, and why: a workspace role, direct access, a sharing link, or an Entra group expanded to its members.
Power BI's real rule
A person needs access to both the report and its semantic model, so the list is who can actually see it.
Everything one person can see
For access reviews, audits and leavers.
Who actually opens what
The last 30 days of the Power BI audit log, refreshed with every scan.
Paid seats nobody uses
Pro and PPU licences with no activity — never flagged without activity data to compare.
What nobody needs any more
Reports and models nobody opens, and refreshes that fail.

Getting connected

One-time setup, and it’s easy.

  1. Register an app

    One service principal in Entra ID, with a client secret. Fabriscope stores it encrypted and never shows it again.

  2. Allow read-only admin APIs

    Two tenant settings for the principal's security group. The connection check tells you which one is missing.

  3. Give it Contributor

    On the workspaces the Data Catalog should document. Report Audience needs no workspace role at all.

  4. Pick workspaces and scan

    One selection serves both products. Schedule up to eight scans a day; each re-reads only what changed.

Security review

Read-only, and specific about what that means.

Fabriscope never creates, changes or deletes anything in your tenant. Its Fabric client refuses every write verb, and a test in its own suite asserts that on every build.

Metadata and audit events. Never rows.

Workspace and item inventory, code definitions, table schemas and Delta commit history, access grants, who-opened-what. No table contents, no report data.

The one awkward part, said out loud

Microsoft's getDefinition API — the only way to read notebook and dataflow code — requires read-and-write permission on the item. So the Data Catalog needs Contributor, and never uses the write half. Report Audience needs no workspace role.

Your organisation, isolated

Every query is scoped to your organisation at the data layer. Deselect a workspace and its lineage is deleted at once, not at the next scan.

The secret stays a secret

Encrypted at rest, write-only through the API, scrubbed from every error before it is stored or logged.

Pricing

One subscription. You pay for the workspaces you scan.

Every plan includes the Data Catalog and Report Audience, every feature and unlimited users. A workspace counts once, whichever products read it. Prices in euros, excluding VAT. We invoice you directly; payment by bank transfer.

18 workspaces Business, €690/month

Team

€390/month

Up to 10 workspaces

One data team's corner of the tenant: its compute, storage and reporting workspaces.

Start with a trial

Business

€690/month

Up to 40 workspaces

Several teams and the reporting estate they share. Most mid-size tenants land here.

Start with a trial

Enterprise

€1,690/month

Unlimited workspaces

The whole tenant, however large, including workspaces created next quarter.

Start with a trial

Data Catalog

  • Table lineage from source to report
  • The code that writes each table
  • Docs, catalog and CSV export
  • Who can read each table
  • Findings: stale, exposed, undocumented

Report Audience

  • Who can see each report, to the person
  • Who opens it, from the audit log
  • Pro and PPU seats nobody uses
  • Dormant reports and models

Every plan

  • Unlimited users, up to 5 admins
  • Up to 8 scheduled scans a day
  • One tenant, one service principal
  • Monthly billing, cancel any time

Free for 7 days The trial is everything in Business — both products on up to 40 workspaces — for 7 days. No card.

Questions a Fabric admin asks first

Does it need us to change how we build?

No. There is nothing to install in your workspaces and no annotations to add. It reads the definitions Fabric already stores, the way they are.

What happens with code it can't fully read?

It says so. A table name built at runtime becomes a "dynamic" edge naming the expression it couldn't resolve; an unrecognised step is counted and listed under collection gaps. Nothing is dropped quietly, because a lineage graph that looks complete when it isn't is worse than none.

How long does the first scan take?

Report Audience's inventory takes seconds and the audit log a few minutes. The Data Catalog takes roughly five to twenty minutes for a few hundred items, because Microsoft rate-limits the definition API. You can watch each step's progress while it runs.

Why is a workspace the unit of price?

It is the one number both products share — the workspace selection is common to both — and it tracks the size of what you are documenting far better than a count of seats. Users are unlimited on every plan.

What if we outgrow our plan?

Choose a larger plan under Settings and the next scan covers the new selection. On a smaller plan, scans simply read the first workspaces up to its limit; nothing collected is deleted.

How do we pay, and who invoices us?

We invoice you directly, monthly, quarterly or yearly in advance, payable by bank transfer within 14 days. VAT follows EU rules: reverse-charged for EU businesses with a VAT number, Slovenian VAT for customers in Slovenia. Purchase orders are welcome. Cancel any time; nothing collected is deleted.

Who can do what?

Three roles, and as many people as you like. Viewers read both products. Contributors also write table and column descriptions. Admins connect the tenant, choose the workspaces to scan and run scans.

Contact

Talk to the person who builds it.

Questions about your estate, a security review, a quote for more than one tenant, or a 30-minute call to get the service principal set up — write directly.

  • Setup call for your Fabric admin
  • Security and data-protection questions
  • Invoicing and procurement

Find out what your estate is made of.