Which reports should we fix, delete, or trust this week?
GaugeSeal watches every report in your Power BI and Tableau estate, holds it to a contract you set, and tells you which ones to fix, delete, or trust this week.
Read-only access to your BI platform, revoked from your side whenever you like. No agent to install, no card, and the demo needs no signup at all.
Harbourline Retail
| Status | Report | Why |
|---|---|---|
| At risk | Replenishment Exceptions | Refresh failures Freshness |
| Insufficient data | Gateway Health | No refresh outcome has ever reached us. Not stale, and not fine. The verdict waits. |
| Underused | Copy of Group P&L (do not use) | Usage Ownership |
| Orphaned | Cost Centre Drilldown (legacy) | Ownership |
| Healthy | 50 of the 100 meet their contract. The board does not ask you to look at them. | |
At risk16Insufficient data8Underused21Orphaned5Healthy50of 100 reports
Five real rows of the demo estate, in the product's own markup — one for each state the engine returns. The live board writes the engine's own sentence of evidence beside every row and links each one to the report behind it.
BI estates accumulate. Expectations stay in people's heads.
Freshness, ownership and readership are almost never written down, so maintenance is reactive by construction: a broken, stale or abandoned report is discovered when somebody complains — and the one an executive decided on last quarter is the one nobody was watching.
- Nobody knows which of these nine hundred reports still matter.
- The regional sales dashboard was wrong for three weeks. Finance found it, not us.
- Whoever built this left in March.
- We find out a refresh has been failing when somebody complains.
Four sentences we wrote down while building this, not quotes from anyone. If none of them are yours, you probably do not need us.
Three good tools, none of them pointed at this
Data observability
Monte Carlo, Soda and their neighbours watch pipelines and datasets. A report can be perfectly fed and still be unowned, unread, or quietly wrong for the decision it is used in — the BI asset itself is not a first-class object down there.
Your platform's own admin views
Power BI and Tableau will both tell you view counts and refresh logs. Neither will tell you what those numbers were supposed to be. Descriptive statistics are not a verdict, and nobody reads them weekly.
Infrastructure monitoring
Datadog and friends know the service is up. They cannot know that a dashboard nobody has opened in two months should be deleted, or that the one that is up is the one nobody owns.
Connect, declare what you expect, read the answer weekly
1 · Connect, read-only
One credential per workspace, read-only, checked before anything is stored — a connection that fails leaves nothing behind. The walkthrough is the same page as the form.
Power BI
Inventory, owners, refresh outcomes and viewer activity, read through an Entra service principal with the Fabric read-only admin APIs.
Tableau Cloud
Workbook inventory, owners and view history, read through a site administrator's personal access token. No refresh outcomes — Tableau does not put them where we can see them.
2 · Declare what you expect
A contract per workspace, overridable per report: how many consecutive refresh failures you tolerate, how fresh a report has to be, how many people have to read it, how slowly it may render. Five rules, no rules language to learn.
A rule you do not declare is not checked, and the screen says so rather than leaving a blank. Every change is a new version, and every verdict names the version that judged it.
Workspace default
| Rule | Expectation |
|---|---|
| Refresh failures | No more than 2 consecutive refresh failures |
| Freshness | A successful refresh within 24h |
| Latency | Not declared |
| Usage | At least 5 unique viewers in the last 30 days |
| Ownership | An accountable owner mapped |
3 · Read the board
Actionable reports first, in the engine's own severity order, each with the evidence underneath it: which rule broke, what we observed, and when it last changed state.
A weekly digest says the same thing in your inbox, so nobody has to remember to look.
Replenishment Exceptions At risk
| Rule | Finding |
|---|---|
| Refresh failures | Breached |
| Freshness | Breached |
| Usage | Met |
| Ownership | Met |
An honest gap beats a confident guess
We never guess
A report we have not watched long enough is not green. It reads Insufficient data until the evidence is actually there, and the screen says which evidence is missing.
Usage never lies
Only identified viewers count towards a viewer minimum. An embedded page whose platform logs a service principal instead of a person is never quietly counted as read — Customer Portal — Usage (embedded) in the demo estate is exactly that case, and we say so rather than inflating it.
Reliability never lies
Refresh outcomes come from the platform's refresh history, never inferred from an audit log and never fanned out from one dataset onto every report that shares it. Where they do not reach us, we say that instead of calling a report stale.
We are not a BI tool about your BI tool
No usage charts, no leaderboards, no score out of a hundred. Health is a state with an action attached: fix it, delete it, or trust it.
Look at an estate that is not yours, then connect one that is
Open the demo
No signup, no card, and nothing you can break. Harbourline Retail is synthetic from top to bottom, read-only to everyone, and regenerated daily.
Connect a workspace
One read-only credential, validated before anything is written: we check the connection, then register the workspace, then seal the secret. A connection that fails stores nothing at all.
What lands when
Inventory and ownership in the first scan, within minutes — unowned reports are actionable that day. Refresh outcomes follow, report by report. Usage is last, and nothing is called underused until a full window has been watched from the beginning.
One EU machine, read-only credentials, and a door you close yourself
Where it runs
A single server in the European Union, rented from an EU company with no US parent. No cross-region replication and no second copy elsewhere.
What we hold
Connector credentials are sealed before they reach the database and the key lives outside it. Personal data is 4 kinds of field, each because a rule cannot run without it, kept for a bounded time and erased by a job rather than by a promise.
How you end it
Access is granted in your tenant, so it is withdrawn in your tenant — we are not in that loop. A workspace can also be deleted outright, and every row it owns goes in one operation.
Take it to your reviewer: the two-page brief, the data processing agreement, or the whole security answer.
See a real estate before you connect anything
A hundred reports of designed sprawl, judged by the same engine that would judge yours. Read-only, no signup, regenerated daily.