Power BI Embedded

Power BI Embedded & Dashboard-as-a-Service (UK)

Power BI Embedded lets a SaaS or platform team ship analytics as a product feature instead of building a charting stack from scratch. Done well, your customers get fast, branded dashboards that feel native to your app. Done badly, tenants can see each other's data or the capacity bill outgrows the feature. We design the embedding model, the tenant security and the capacity plan, build them on a fixed scope, and can run the service as your user base grows.

Yes. Turing BI designs and builds Power BI Embedded analytics for SaaS products and customer portals: white-label, multi-tenant dashboards secured with row-level security and served from embedded capacity, so your customers see their own data inside your product without needing Power BI licences of their own.

01Why it matters

The two decisions that make or break embedded analytics are taken at the start: how users authenticate, which sets the licensing model, and how tenants are isolated, which sets the security model. In the app-owns-data pattern your application authenticates with a service principal and requests an embed token per session, so viewers never sign in to Power BI and never need licences; you pay for capacity instead. Getting the token design and row-level security right first matters, because retrofitting security into a live product is far harder than scaling capacity.

What you get

  • Analytics shipped as a product feature, not a side project
  • Tenant isolation you have watched being tested
  • No per-viewer Power BI licences for your customers
  • Capacity cost that scales with usage, not headcount
  • A documented build your team owns

App-owns-data vs user-owns-data

In user-owns-data, viewers sign in with their own Power BI licences: workable for internal portals, wrong for customers. In app-owns-data, your app authenticates and requests embed tokens, so external users need no licence and never touch Power BI. For customer-facing SaaS the answer is almost always app-owns-data, and we confirm it against your product and audience before anything is built.

Multi-tenant row-level security

One shared semantic model with RLS roles filtered by the tenant id in the embed token usually beats a workspace per customer, which stops scaling past a handful of tenants. We design the tenant key into the model, generate tokens with the right identity, and test isolation with deliberately hostile cases, because one customer seeing another's numbers is a churn event and possibly a reportable breach.

White-label, inside your product

White-labelling is more than a logo swap: report themes matched to your palette and typography, Power BI chrome hidden through the embedding API, your own navigation and filter controls in the host app, and loading states that feel native. The result reads as your product's analytics, not a Power BI report in an iframe.

Capacity & licensing model

App-owns-data runs on dedicated capacity: Microsoft Fabric F-SKUs, or legacy Azure A-SKUs, billed by capacity size rather than per viewer. We start at the smallest viable SKU, measure concurrent render and refresh load, and scale on evidence, so the feature has unit economics you can price into your plans. Confirm current Microsoft pricing before you budget.

Token service & integration

Your backend needs a small, secure endpoint that authenticates with a service principal, requests embed tokens scoped to the right report and RLS identity, and handles expiry. We specify it, or build it with your developers, along with the workspace structure and deployment pipeline for dev, test and production.

Performance & scale

Embedded users judge your product, not Power BI, so render time is a product metric. We model the data for query speed, watch the capacity metrics that predict throttling, and set refresh cadence so busy periods never degrade the dashboards your customers pay for.

02How we work
01

Design

A Trusted Numbers Review scopes the embedding model, tenant security, capacity size and integration plan against your product and expected usage, and quotes a fixed price for the build. The review fee comes off the work.

02

Build

Semantic model, RLS roles, reports and themes built on the fixed scope, with embed-token integration done alongside your developers.

03

Prove

Tenant isolation tested with adversarial cases, numbers reconciled to source, and render performance measured under realistic concurrency before any customer sees it.

04

Run

Optional managed service: refresh monitoring, capacity right-sizing as usage grows, and new reports as your product roadmap needs them.

03FAQ
Can we embed dashboards in our SaaS product without every user needing a licence?

Yes. That is exactly what the app-owns-data model is for: your application authenticates with a service principal and requests embed tokens, and your customers view reports through your embedded capacity. They never sign in to Power BI and never need individual licences; you pay for capacity sized to concurrent load instead.

How does row-level security work for multi-tenant?

Reports run against a shared semantic model with RLS roles that filter every table by tenant. When your app requests an embed token it passes the signed-in customer's identity, and the model returns only that tenant's rows. We design the tenant key into the model from the start and test the isolation deliberately, including trying to break it, before launch.

What does embedded capacity cost?

It is billed by capacity size (Fabric F-SKUs, or legacy A-SKUs), not per viewer, and the right size depends on concurrent renders and refresh load rather than raw customer count. We start with the smallest viable SKU and scale on measured usage. Microsoft pricing and SKU options change regularly, so confirm current pricing before you budget.

Can the embedded reports match our product's branding?

Largely, yes. Report themes control colours and fonts, the embedding API hides Power BI chrome, and your app supplies the navigation and filtering around the report. There are limits: you are styling Power BI visuals, not writing custom charts, so we confirm the look you need is achievable during design rather than discovering it during build.

What do you need from our development team?

A well-defined integration: a backend endpoint that issues embed tokens, the embedding component in your front end, and a way to pass the signed-in customer's identity. We provide the specification and work alongside your developers; the model, security and report work stays on our side.

Let's talk

Let's scope your project.

A fixed price agreed in writing before we start, and you own everything we hand over.