Embed and govern Power BI per tenant

Proceptio PowerCRM puts embedded analytics, automated dataset refresh, scheduled report subscriptions, row-level security, and per-tenant access control in one platform, on a secure multi-tenant SaaS foundation.

Embedding a report takes an afternoon. Deciding who may open it takes the other eleven months.

Multi-tenant
Per-tenant workspace isolation
RLS
Row-level security by user or role
Automated
Scheduled dataset refresh
Scheduled
Email report subscriptions

Power BI, embedded and governed. For every tenant at once.

Everything you need to deliver analytics to every tenant, under control.

Power BI for many tenants, under control

Embedding a report is the easy part. What makes this a platform rather than an iframe is everything around it: who may see which report, when it refreshes, who actually opened it, and what the capacity costs. Follow one report through all five.

Power BI Embedded, Microsoft Fabric. Multi-tenant, per-tenant workspaces.

01

One place that knows about every report you publish

Reports and dashboards are registered per tenant and mapped to that tenant's own workspace, so a tenant only ever reaches its own data. The list carries the state that matters to whoever runs it: which report is up to date, which is refreshing, and which one failed and needs attention now.

02

Refreshed on a schedule, and delivered without anyone asking

Set the frequency, the days and the times, and the recent-refresh history is right there beside them so a retry is visible rather than silent. Subscriptions send the report to a list of recipients as a file on their own cadence, which is how most people actually want a report: in their inbox, already run.

03

The part that decides whether you can sell this to a tenant

Access is granted by individual user or by role, and Row-Level Security roles are mapped so the filtering happens inside the model rather than in the page around it. Enforcing RLS is a switch, not a project, and capacity is suspended and resumed automatically so an idle tenant does not bill like a busy one.

04

Every view, refresh, export and failure on the record

The log names the tenant, the user, the report and the event, so "is anyone actually using this?" and "why did Tuesday's report not arrive?" both have answers you can read rather than guess. Errors and capacity events sit in the same timeline as the ordinary views.

05

The view the operator needs, not the one a tenant needs

Above all the tenants there is one dashboard: how many there are, how many subscriptions are live, which editions they are on, and whether capacity is running. That is the difference between a report embedded in an app and a multi-tenant analytics product somebody operates.

A complete SaaS foundation

The enterprise plumbing under the analytics, built in.

01

Editions & billing

Editions, subscriptions, and invoicing out of the box.

02

Roles & permissions

Granular permissions, roles, and organization units.

03

Audit logs

A full audit trail of who did what, and when.

04

Multi-language

Localize the platform for every tenant and user.

05

Light & dark theming

Per-user themes across the whole application.

06

Webhooks

Push events to downstream systems on change.

Integrations & automation

Microsoft Teams

A failed refresh or a missed delivery lands in the channel that owns it, so the first person to notice is not the tenant.

ServiceNow

Tickets and workflows connect to the platform's own events, so an analytics problem becomes a tracked item rather than an email.

ETL on Hangfire

Data pipelines run as background jobs with their own retry and history, which is what makes a refresh schedule something you can inspect.

GraphQL API

Query tenants, reports, subscriptions and logs programmatically, for the reporting your own operations team wants about the platform itself.

Xamarin mobile

Native mobile apps on the same platform, identity and permissions, for the people who approve rather than analyse.

You would not be the first thing built on it

PowerCRM is not a demo we assemble per client. It is the base four other Proceptio products already run on, so the tenancy, identity, permissions and audit under your analytics have been carrying production traffic for years.

The MCP connector host, the identity-broker sign-in, the permission gates and the guarded-write pattern port with the base, which is why an AI layer on top of your tenants is a configuration question here rather than a second project.

See what these systems did

Questions that come before the demo

Is this just a Power BI report in an iframe?
No, and the difference is everything around the report rather than the report itself. Embedding a report takes an afternoon. What takes a platform is deciding who may see which report, mapping each tenant to its own workspace, refreshing datasets on a schedule and proving they refreshed, emailing the output to people who never sign in, keeping a usable record of who opened what, and stopping idle tenants from billing like busy ones. PowerCRM is those parts.
How does a tenant end up seeing only its own data?
Two layers, and both matter. Reports are registered per tenant and mapped to that tenant's own workspace, so a tenant cannot reach another tenant's report at all. Inside a report, Row-Level Security roles are mapped so the filtering happens in the model rather than in the page around it, which means an export carries the same filtering the screen did. Enforcing RLS is a switch, not a project.
What stops Power BI capacity costing more than the product earns?
Capacity is suspended and resumed automatically, and it resumes ahead of a scheduled refresh so nobody meets a cold report. That is the mechanism that lets an idle tenant stop billing like a busy one. The capacity log sits in the same timeline as ordinary views, so a suspend or resume is something you can read rather than infer from an invoice.
Can we send a report to someone who never signs in?
Yes. Subscriptions deliver the report as a file to a list of recipients on their own cadence, in a chosen format, and every delivery is logged. In practice this is how most people want a report: in the inbox, already run. The refresh history sits beside the schedule in the same panel, so a retry is visible rather than silent.
Can we tell whether anyone is actually using a report?
That is what the operational logs are for. Every view, refresh, export and failure is recorded against the tenant, the user and the report, filterable by all three. It answers the two questions that otherwise get guessed: is this report earning its capacity, and why did Tuesday's delivery not arrive.
Is PowerCRM only about Power BI?
The analytics layer sits on a full multi-tenant application framework, which is why it can be sold as a product rather than assembled per client. Tenants, editions, subscriptions and invoicing, users, roles and granular permissions, organization units, audit logs, multi-language and theming are all part of the platform, with webhooks and a GraphQL API for whatever comes after.
Which Microsoft services does it run on?
Power BI Embedded and Microsoft Fabric, with per-tenant workspaces. It is built and operated by Proceptio on the Microsoft stack, by the same team that runs the rest of the platform work.