Microsoft Fabric workspace management, governance, REST API patterns, and medallion architecture implementation
tier
standard
applyTo
**/*fabric*,**/*lakehouse*,**/*medallion*
user-invokable
false
Microsoft Fabric Governance Skill
⚠️ Staleness Watch (Last validated: Feb 2026 — REST API v1): Microsoft Fabric ships major features monthly. Monitor the Fabric release notes for new item types, API surface changes, and Git integration improvements. The REST API base URL (api.fabric.microsoft.com/v1) is stable but new endpoints are added regularly.
Overview
Expert knowledge for Microsoft Fabric workspace management, governance, and documentation. Covers REST API patterns, medallion architecture implementation, permission compliance pipelines, and automated workspace inspection.
Key Insight: Gold layer benefits from schema-enabled lakehouses for domain organization while Bronze/Silver remain standard for ingestion flexibility.
3. Permission Compliance Pipeline
7-Step CPM Pattern:
graph LR
A["📥 Copy<br/>Contacts"] --> B["🔐 MSWide<br/>Perm API"]
B --> C["🔐 TXN<br/>Perm API"]
C --> D["✅ CPERM<br/>Validation"]
D --> E["🌍 Country<br/>Enrichment"]
E --> F["💧 Data<br/>Hydration"]
F --> G["📤 Load<br/>Lakehouse"]
style A fill:#ddf4ff,color:#0550ae,stroke:#80ccff
style B fill:#d8b9ff,color:#6639ba,stroke:#bf8aff
style C fill:#d8b9ff,color:#6639ba,stroke:#bf8aff
style D fill:#d3f5db,color:#1a7f37,stroke:#6fdd8b
style E fill:#fff8c5,color:#9a6700,stroke:#d4a72c
style F fill:#ddf4ff,color:#0550ae,stroke:#80ccff
style G fill:#d3f5db,color:#1a7f37,stroke:#6fdd8b
linkStyle default stroke:#57606a,stroke-width:1.5px
Permission Tables:
CPERM_OptOut - Marketing opt-outs
US_FAR_List - US government exclusions
US_CAPSL_List - CAPSL compliance
SpamHaus_List - Known bad actors
4. Unity Catalog Integration
Schema-Enabled Lakehouse Access:
# Catalog URL pattern
catalog_url = f"https://onelake.table.fabric.microsoft.com/delta/{workspace_id}/{lakehouse_id}"# List schemas
GET /schemas
# List tables in schema
GET /schemas/{schema_name}/tables
Domain Organization:
Use schemas for domain separation (dbo, CxPulse)
Enable for Gold layer business domains
Keep Bronze/Silver as standard for flexibility
5. PowerShell Automation
Workspace Scanner Pattern:
# Use Invoke-WebRequest for header access (not Invoke-RestMethod)
$response = Invoke-WebRequest -Uri $uri -Headers $headers -Method Post
# Handle 202 Accepted
if ($response.StatusCode -eq 202) {
$operationUrl = $response.Headers["Location"][0]
# Poll for completion
do {
Start-Sleep -Seconds 2
$status = Invoke-RestMethod -Uri $operationUrl -Headers $headers
} while ($status.status -ne "Succeeded")
# Get result
$result = Invoke-RestMethod -Uri "$operationUrl/result" -Headers $headers
}
Documentation Patterns
Inventory Structure
Executive Summary - Metrics and architecture overview