Governance

Govern an estate you did not build and cannot see

Ownership, sharing, credentials, premium reach and environment sprawl across the whole tenant — read-only, refreshable, and installed nowhere.

You cannot govern what nobody has ever listed

Power Platform estates are built by makers, not by projects. Apps appear in default environments, flows run on a leaver's personal connection, premium connectors turn up in trials, and the only copy of something important is a solution somebody exported once.

None of it is hidden. It is spread across four Microsoft admin APIs, each paginated, each throttled, none of which will hand you a single sentence about the whole tenant. Power Insights reads all four and gives you that sentence — and the list behind it — from the first sign-in.

makerOwnership

Who owns this, and are they still here

Every app and flow carries its owner, and the estate carries the ones whose owner has left. An app running a finance process owned by somebody who went in March is not a governance abstraction — it is an outage with a date on it.

  • Owner and last modified on every object
  • Objects whose owner no longer resolves in the directory
  • Ownership concentrated in one or two people, made visible
securityExposure

Who can open what

Everyone an app is shared with and at what level, including anything shared with the entire tenant. Sharing is read live rather than from the stored assessment, because it is the figure most likely to have changed since the last sync.

  • Users and groups per app, with their permission level
  • Tenant-wide sharing called out rather than counted
  • Sharing reach on the list, so the outliers are visible without opening anything
ConnectionsCredentials

The connections nobody remembers making

A connection is an identity. Knowing which account a production process authenticates as — and whether that account belongs to a person — is the question that decides how much of the estate is one leaver away from stopping.

  • The account each connection runs as, where the API discloses it
  • Health status and whether it is shared beyond its owner
  • Everything downstream that would break if it went away
ConnectorsLicensing

Premium reach, without the guesswork

Standard, premium and custom connectors ranked by real usage across the tenant. Premium reach is a licensing question and a security one, and the same list answers both.

  • Usage merged from apps, flows and connections
  • Licence tier per connector
  • Custom connectors with the backend host they call
Power PlatformSprawl

Every environment, including the ones you forgot

Production, sandbox, developer, trial, Teams and default. The default environment is usually the largest and the least governed, and it is the one nobody has a list of.

  • Type, region and state for every environment
  • Managed Environment status, so governance gaps are visible
  • What each one holds, object by object
reportReporting

Answers before the audit asks

Prepared views over the stored assessment — governance, security, connectors, environments — and the whole thing exportable in a shape somebody without a licence can read.

  • Governance and security reports over the current assessment
  • Excel, PDF, JSON and CSV exports of any of it
  • Refresh whenever you need the picture brought up to date

Alongside the CoE Starter Kit

Where each one is strongest

Microsoft's Center of Excellence Starter Kit is a free, open-source toolkit that many tenants rely on, and it does things Power Insights deliberately does not. This is a plain account of which tool covers what, so you can decide whether you need one, the other, or — as is common — both.

CapabilityCoE Starter KitPower Insights
Where it runs
Deployment model
Solutions installed into a Dataverse environment in your tenant, with flows, tables and Power BI reports
Hosted service outside your tenant; reads through Microsoft's admin APIs with your sign-in
Writes to your tenant
By design — its processes act on apps, flows and makers
Read-only by default; a few labelled actions (share with me, create a solution) run only when you start them
Several tenants from one place
One installation per tenant
Enterprise plan: connect several tenants to one account (MSPs, partners)
Inventory and visibility
Environments, apps, flows, connectors, connections
Core components sync flows, on a schedule
Assessment in minutes, refreshed on demand
Solutions, Dataverse tables and connection references
Solutions are inventoried; table and column schema is not the focus
Solution membership per object, tables with columns, connection references resolved
Ownership, sharing reach and orphaned objects
Owner and shared-with data, orphaned-object handling
Owner, shared-with count and list per app, leavers flagged, users-per-app export
Premium connector and licensing exposure
Power BI dashboards on connector usage
Connectors ranked by real usage with tier, per environment
Search inside app packages and flow definitions
No
Hard-coded URLs, SQL statements and stored procedures, SharePoint and Power BI references, action counts
Estate map and cross-environment reports
Power BI dashboards per area
Interactive map, governance and pre-migration reports, Excel and PDF export
Governance processes
DLP policy impact analysis and editor
A strength of the kit
Shows connector reach; does not model or edit DLP policies
Compliance requests, app archival, inactivity clean-up
Governance components with maker-facing flows
Read-only — reports what is stale, does not archive it
Maker onboarding, welcome emails, nurture
Nurture components
No
Migration
Dependency detection and migration plan
No
Per-app dependencies, kanban with notes and stages, refresh plan with findings
Collections across environments and solution creation
No
Pick apps and flows from any environment; preflight and create a Dataverse solution from them
Read-only sharing with stakeholders
Power BI sharing, with Power BI licences
Expiring share links, no sign-in needed for the reader

Effort to get there, and to stay there

Typical figures, not promises. Yours will depend on the size of the tenant and how much of the kit you deploy.

AspectCoE Starter KitPower Insights
PrerequisitesA dedicated environment with Dataverse, a service account with an admin role, Power Automate premium licensing for that account, Power BI Pro for the dashboardsAn administrator account and a browser. A Dataverse security role is needed only for solution, table and connection-reference detail
Initial set-upTypically 1–3 working days for an experienced administrator; 1–2 weeks elapsed once licensing and service-account approvals are includedAbout 10 minutes: sign in, run the assessment
Time to first complete pictureAfter the first full sync — several hours to a day on a large tenantMinutes for most tenants; under an hour for the largest
Ongoing maintenanceMonthly releases to import and test; sync flows to monitor and repair. Typically 2–4 hours a month, more after a breaking changeNone on your side — refresh is one click and the product is maintained for you
Skills neededSolution import, Power Automate, Dataverse, Power BIUsing a web application
Cost modelThe kit itself is free; the cost is licences for the service account and Power BI, plus people timeSubscription, with a free plan for a single environment. No licences to buy in your tenant

Estimates are drawn from LogiSam's own deployments and Microsoft's published set-up guidance for the CoE Starter Kit, as at 2026. The CoE Starter Kit is a Microsoft project; Power Insights is an independent product by LogiSam and is not affiliated with or endorsed by Microsoft.

See your estate as it actually is

One assessment, every environment, nothing installed. The free plan covers a single environment for real.

Power Platform governance and Center of Excellence (CoE) visibility · Power Insights