Why governance is built in, not bolted on#

In most platforms, governance is a separate tool bolted on after the fact. In Fabric, it's centralized in the OneLake Catalog and powered by built-in Microsoft Purview: permissions, sensitivity labels, and auditing apply automatically and inherit across items, staying enforced even across tenant boundaries [S2]. Fabric's governance surface spans four areas: the data estate (domains, workspaces, capacities, metadata scanning), security (sensitivity labels, DLP, auditing), discovery and trust (the OneLake catalog, endorsement, lineage), and monitoring [S1].

Fabric governance layers across tenant, domain, workspace, and item boundaries

The three-tier hierarchy#

Governance settings cascade through three tiers: tenant-wide defaults set by Fabric admins, domain-level overrides applied by domain admins for delegated settings, and workspace-level controls managed by workspace owners for the most granular scope [S1]. Domains group content by business area, can contain subdomains, and let workspace content be filtered by domain in the catalog [S1].

Sensitivity labels and protection#

Sensitivity labels, defined in Microsoft Purview Information Protection, classify items — reports, semantic models, lakehouses — into levels like General, Confidential, or Highly Confidential, using the same taxonomy as Microsoft 365 [S3] [S4]. Labels apply manually, by default, via inheritance, or via a mandatory policy, and persist even when data is exported, such as into Excel [S1] [S6]. Purview DLP policies scan supported item types on upload, log detections to the audit log, and can alert data owners when proprietary content is found [S1].

Where to look: the OneLake catalog#

The OneLake catalog is the single searchable surface for every item a user can access, with domain- and tag-based filtering [S1]. As of the end of January 2026, the standalone Purview Hub was retired; its insights moved into the catalog's Govern tab [S5]. Govern-tab insights refresh roughly daily, reflecting the prior day — check the Secure tab for live, current permission assignments [S5]. Endorsement adds a trust signal: owners self-apply Promoted status, organizations apply Certified status, and both get priority placement in search and catalog views [S1].

A worked example#

An analyst publishes a semantic model to a workspace in the Finance domain. Because the workspace inherits the domain's delegated settings, a default Confidential label applies automatically — no manual step needed [S1]. A colleague exports a summary to Excel; the label travels with the file rather than being stripped [S6]. A steward checks Govern weekly for label coverage, but to confirm who has access before an audit, uses Secure instead, since Govern reflects only yesterday's snapshot [S5].

What goes wrong#

  • Assuming Govern-tab numbers are live. They refresh about once a day; use Secure for current permissions [S5].
  • Expecting a workspace to fully control its own governance. Only settings delegated from tenant or domain level are workspace-configurable [S1].
  • Assuming exported data loses its label. Labels persist through supported export paths [S1] [S6].
  • Confusing base licensing with full Purview governance. Information Protection, DLP, and cross-org governance can need licensing beyond base Fabric [S1].