Docs · updated October 2026

Security & permissions

What Fabriscope reads, what it keeps, where, and why it can be trusted to stay read-only.

Read-only

Fabriscope never creates, changes or deletes anything in your tenant. Its Microsoft client refuses every write call outright; the only calls it makes are reads. The warehouse SQL endpoints are opened read-only and only ever sent fixed metadata queries.

The one permission that sounds otherwise is Contributor on the workspaces you document, because Microsoft's API for reading item definitions requires it. See Connecting your tenant.

What it reads

ReadNot read
Workspaces, items, their definitions (code), table schemas, Delta commit history, job runsRows in your tables
Access: workspace roles, item permissions, OneLake roles, group membersData in your reports and semantic models
The Power BI audit log: who opened what, whenFiles, mail or anything outside Fabric and Power BI
Licence assignments (optional, Microsoft Graph)

Where it is stored

The service and its database run in the European Union, in Microsoft Azure's Sweden Central region. Your service principal's secret is encrypted with a key kept outside the database, and never shown or returned again. Every organisation's data is separated in the data layer: one customer never sees another's.

The audit log is kept for a rolling 30 days. See the privacy policy for personal data, and ask for a data processing agreement at info@fabriscope.com.

Revoking access

You stay in control: delete the client secret or the app registration in Entra ID, remove the principal from the security group or the workspaces, or choose Disconnect in Settings, which also deletes everything collected.