RLS Persona Tester / v0.1.1POWER BI + MICROSOFT FABRIC

Catch Power BI
RLS leaks before they ship.

RLS Persona Tester runs your semantic model as every configured persona, flags data it shouldn’t see, and fails the test step in CI.The security test your BI pipeline is missing.

Your auth. Your tenant. No model data sent to us.

rls-persona-tester
$rls-test -c demo_config.json
connector simulated testing declared personas
✓ PASSNorthscope_leak
✓ PASSNorthvalue_scope
✓ PASSSouthscope_leak
✕ FAILEMEA_leakyscope_leak
✕ Data outside the allowed scope
Expected ['EMEA']
Observed ['North', 'South', 'EMEA']
[FAIL]47 checks · 12 failed · 35 passed
Illustrative seeded-demo output · a non-zero exit stops the CI test step.
Built forPower BI+Microsoft FabricmacOS · Linux · WindowsConsole · JSON · JUnitRuns locally. Queries your tenant.
01 /The blind spot

RLS is a security control.
“View as role” isn’t
a test suite.

Row-level security decides who sees what. One wrong filter and a user sees another region’s, client’s, or department’s numbers — a security, compliance and audit failure.

Yet teams still test it by hand with spare accounts and a quick look at “View as role”. It’s slow, partial, and the first thing skipped under deadline.

The wrong user. The wrong data.

A small model change can expose data outside a persona’s intended scope.

A check that gets skipped.

More roles, more test accounts, more manual checks before every release.

No repeatable release gate.

An eyeballed result isn’t a regression test you can rerun in your pipeline.

02 /One command. A real release gate.

Declare intent. Test every persona.
Fail the build on a leak.

Turn the access rules you expect into checks your pipeline can enforce.

01

Define what “allowed” means.

Point it at a published semantic model. Map a test user to each role, choose your measures, and declare the members each persona should see.

02

Query as each persona.

The CLI impersonates each configured user over the executeQueries REST API, then runs the checks against that user’s actual view.

03

Stop when reality differs.

Compare what each persona can see with what it should see. A failed check returns a non-zero exit code to stop your CI test step.

# With your configuration and licence key environment variable set
pip install 'rls-persona-tester[rest]'
rls-test -c your_model.json -f junit -o results.xml
Start with the free demo
03 /What it catches

Five checks.
Fewer places for a leak to hide.

From a role that sees nothing to one that sees far too much. Test the data, not just the role definition.

RLS checks, the failures they detect, and the configuration each check needs
CheckWhat it catchesWhat you declare
01empty_viewBroken or over-restrictive RLS: a role sees nothing on key measures.No scope mapping required
02exceeds_unrestrictedA hard leak: a role’s measure exceeds the unrestricted model total.No scope mapping required
03scope_leakA role sees dimension members outside its allowed scope.Allowed members per role
04value_scopeA role’s measure differs from the measure over its allowed scope.Allowed members per role
05reconciliationRoles don’t cover the unrestricted total exactly once — overlap or gaps.A partition of roles
✓ PASS Correctly restricted✕ FAIL Leaky persona

Checks evaluate your declared scopes and measures. A passing run is not a guarantee of complete security coverage.

04 /Built for the way BI engineers work

A CLI, not another platform.

Your machine. Your workflow.

A cross-platform Python CLI. No Power BI Desktop, no .NET, and no Fabric notebook needed for REST testing.

macOS / Linux / Windows · Python 3.9+

Built to fail the build.

Readable console output, JSON for automation, and JUnit for your test runner. Failed checks return a non-zero exit code.

console / JSON / JUnit · non-zero on failure

Knows the Direct Lake trap.

Recognises the common Direct Lake + SSO impersonation failure and explains the connection change, instead of leaving you with an opaque error.

PowerBIEntityNotFound → actionable diagnosis

The REST connector uses user authentication. Service principals are not supported for RLS models on this API; unattended XMLA-based testing is on the roadmap.

05 /Start without a tenant

See a leak caught.
In 30 seconds.

Run the free, offline demo against a simulated model with deliberately broken roles. See exactly what passes — and what should stop a release.

  • No account. No card. No licence key.
  • No Power BI or Fabric setup.
  • Free offline demo and preflight, forever.

v0.1.1 · Python 3.9+ · core uses the standard library

First, download demo_config.json to your working directory. Then run:

shell
pip install rls-persona-tester
rls-test -c demo_config.json
Illustrative output excerpt
✓ PASSNorth   scope_leak
✓ PASSSouth   value_scope
✕ FAILEMEA_leaky   scope_leak
[FAIL] 47 checks · 12 failed · 35 passed
The demo is supposed to fail. Planted leaks produce exit code 1. That’s the release gate working.
06 /Simple pricing. Serious checks.

Prove it free.
Test your real models
for $99 a year.

Start with the same checking engine. Add a licence when you’re ready to test your own Power BI and Fabric semantic models.

Free, forever.

The offline simulated demo and --preflight connectivity diagnostics. No card required.

Free and licensed functionality comparison
IncludedFreeLicence
Offline simulated demo✓✓
Preflight diagnostics✓✓
Live tests against your models—✓
Licensed product updates—✓
Try the demo first
DEVELOPER LICENCEBILLED YEARLY
$99/ yearUSD

Everything in the free demo, plus live testing against your real models and updates.

  • Live Power BI & Fabric RLS tests
  • All five checks against declared intent
  • Console, JSON and JUnit output
  • One developer’s machines + CI
  • Product updates during your subscription
Get a licence — $99/yr

Secure checkout via Polar

Billed annually in USD. Cancel renewal anytime.
Applicable taxes calculated at checkout.
Refund policy pending publication

07 /Built from the work
10+YEARS IN
BUSINESS INTELLIGENCE

Built by a BI engineer.
Not a marketing department.

RLS Persona Tester is built by Green Analytics Ltd, a UK company led by a BI engineer with more than a decade in Business Intelligence. Made for the gap between defining access and proving what a user actually sees.

A documented engineering problem

The need for RLS validation is real.

Tabular Editor issue #1198 asked how to validate RLS configuration. Persona-level regression testing goes a step further: checking the data returned for each configured user, not only the presence of role rules.

Independent product. Not affiliated with Microsoft or Tabular Editor.

08 /Before you run it

The practical questions.

Requirements, data handling and the things worth knowing before you buy.

Ask the developer
What do I need to run live tests?

A model on Premium, PPU or Fabric capacity; the tenant setting “Dataset Execute Queries REST API” enabled; model Read and Build permissions; and a test user per role, assigned in the model’s Security settings. A Fabric trial covers the capacity requirement.

The REST connector uses MSAL user authentication. Run the free --preflight check before purchasing to diagnose connectivity and permissions. Impersonation may require elevated model permissions; use a controlled test setup and confirm the requirements for your tenant.

Does it work on a Mac?

Yes. It’s a cross-platform Python CLI using HTTPS for the REST connector. It runs on macOS, Linux and Windows with Python 3.9 or newer. No Power BI Desktop or .NET installation is needed.

Can I use it in CI?

Yes — it emits console, JSON or JUnit results and a non-zero exit code on failed checks. Configure your pipeline to stop when the command fails.

The current REST connector uses user authentication. Microsoft’s Execute Queries API does not support service principals for RLS models, so fully unattended service-principal CI is not supported through this connector. XMLA-based testing is on the roadmap.

Is my data safe?

Queries run directly between the CLI on your machine or runner and your Microsoft tenant, using your authentication. Model data is not sent to Green Analytics Ltd. Licence validation uses your licence key, not your model data.

Test output can contain measure values and visible dimension members. Treat local results and CI artefacts as sensitive and restrict access accordingly.

How is my card handled?

Payments are handled by Polar as merchant of record. We never see your card details. Polar handles applicable VAT and sales taxes at checkout.

What is the refund policy?
PENDING PUBLICATION

The refund policy has not been published yet. Please contact Green Analytics Ltd before purchasing to confirm the applicable terms. No refund period or guarantee is implied.

What’s on the roadmap?

An XMLA connector to activate roles by name and support unattended CI at scale; a sempy notebook connector for Direct Lake-native impersonation; and richer reporting and CI integration.

These are planned capabilities, not features included in the current release. Buy based on what the tool does today.

Make security part of the release

Make the next leak a failed build.

Not an incident. Not a customer email. A test you can fix before release.

RLS Persona Tester$99 / year · USD
Get a licence
PENDING PUBLICATION

Product information

Contact: [email protected]