
Data Governance
Part of Self-service analytics
Defining which users can build their own reports
Set practical criteria for report creators, distinguish Build from edit and publishing rights, and review access as roles change.
Give report-building capability to people who can explain the data they will use, reproduce an agreed figure and work within a defined sharing boundary. Decide separately who may change a shared dataset and who may distribute a report more widely.
Define permissions by task
Start with the work each person needs to do. A viewer reads an approved report. A report creator builds a new view from an existing dataset.
A dataset owner changes measures or relationships. A publisher makes content available to a wider audience. One person may fill several roles, but each responsibility still needs a decision.
In Power BI, Build permission allows creation of content from a semantic model. It can also allow access to underlying data through export or other client tools, so consider the data exposure before granting it.
Build permission is distinct from permission to edit the original model. Publishing to a workspace requires an appropriate workspace role, and licensing and capacity can limit where a creator may save or share a report. Check the current tenant configuration before assigning permissions.
Permissions in Power BI: Build vs Edit vs Publish
- Build PermissionAllows creating reports from a semantic model. May include data export access. Requires careful control due to potential data exposure.
- Edit Permission (on dataset)Grants ability to modify the underlying semantic model, including measures and relationships. Higher risk than Build.
- Publish PermissionRequires appropriate workspace role and licensing. Enables distribution of content to wider audiences.
Use a small eligibility exercise
Ask a prospective creator to:
- State the business question and intended audience.
- Choose an approved dataset and explain its population and update point.
- Reproduce an agreed total for a fixed period.
- Change a filter and explain the result.
- Identify an uncertainty to disclose or refer to the data owner.
This is a proposed exercise, not an assessment already performed. A missed step may point to unclear dataset documentation or a need for coaching rather than a permanent restriction.
Grant a bounded first use
Start with a named dataset, a draft location and a limited audience. Explain which supplied measures creators can use and which new calculations need review. Make the access route and approval owner clear so people can request what they need.
A report built for personal exploration may contain unresolved assumptions. When it becomes a recurring team report, give it a business owner and check its figures and audience. Reports with sensitive detail, high consequence or broad reach warrant a more formal release decision.
Granting bounded first use for report creation
- Start with a named datasetApproved and documented dataset from central repository
- Use a draft workspace locationRestricted to internal team workspace
- Limit initial audience to team members onlyNo public or cross-team sharing initially
- Define allowed measures and review process for new calculationsOnly pre-approved measures may be used; new DAX requires data owner review
- Assign clear access route and approval ownerCreator must request changes via designated data steward
Revisit access when work changes
Review access when a creator changes team, a dataset gains sensitive fields or a report's purpose expands. In Power BI, removing someone from an app audience does not automatically remove Build permission already granted on its underlying semantic model. Check the person's effective model access, including grants through related items, when withdrawing access.
Keep a brief decision record: person or group, dataset, permitted activity, approving owner and review trigger. It gives creators a clear boundary and helps owners maintain it.
Key considerations when reviewing report creator access
- Review triggers
- Team change, sensitive field added, expanded report reach
- Access not automatically revoked
- Removing from app audience does not remove Build permission on underlying model
- Effective access check required
- Review all grants, including through related items and workspaces
- Decision record kept
- Includes person/group, dataset, permitted activity, approving owner, review trigger



