Define what “allowed” means.
Point it at a published semantic model. Map a test user to each role, choose your measures, and declare the members each persona should see.
RLS Persona Tester runs your semantic model as every configured persona, flags data it shouldn’t see, and fails the test step in CI.The security test your BI pipeline is missing.
Your auth. Your tenant. No model data sent to us.
Row-level security decides who sees what. One wrong filter and a user sees another region’s, client’s, or department’s numbers — a security, compliance and audit failure.
Yet teams still test it by hand with spare accounts and a quick look at “View as role”. It’s slow, partial, and the first thing skipped under deadline.
A small model change can expose data outside a persona’s intended scope.
More roles, more test accounts, more manual checks before every release.
An eyeballed result isn’t a regression test you can rerun in your pipeline.
Turn the access rules you expect into checks your pipeline can enforce.
Point it at a published semantic model. Map a test user to each role, choose your measures, and declare the members each persona should see.
The CLI impersonates each configured user over the executeQueries REST API, then runs the checks against that user’s actual view.
Compare what each persona can see with what it should see. A failed check returns a non-zero exit code to stop your CI test step.
# With your configuration and licence key environment variable set
pip install 'rls-persona-tester[rest]'
rls-test -c your_model.json -f junit -o results.xmlStart with the free demo From a role that sees nothing to one that sees far too much. Test the data, not just the role definition.
| Check | What it catches | What you declare |
|---|---|---|
01empty_view | Broken or over-restrictive RLS: a role sees nothing on key measures. | No scope mapping required |
02exceeds_unrestricted | A hard leak: a role’s measure exceeds the unrestricted model total. | No scope mapping required |
03scope_leak | A role sees dimension members outside its allowed scope. | Allowed members per role |
04value_scope | A role’s measure differs from the measure over its allowed scope. | Allowed members per role |
05reconciliation | Roles don’t cover the unrestricted total exactly once — overlap or gaps. | A partition of roles |
Checks evaluate your declared scopes and measures. A passing run is not a guarantee of complete security coverage.
A cross-platform Python CLI. No Power BI Desktop, no .NET, and no Fabric notebook needed for REST testing.
Readable console output, JSON for automation, and JUnit for your test runner. Failed checks return a non-zero exit code.
Recognises the common Direct Lake + SSO impersonation failure and explains the connection change, instead of leaving you with an opaque error.
The REST connector uses user authentication. Service principals are not supported for RLS models on this API; unattended XMLA-based testing is on the roadmap.
Run the free, offline demo against a simulated model with deliberately broken roles. See exactly what passes — and what should stop a release.
v0.1.1 · Python 3.9+ · core uses the standard library
First, download demo_config.json to your working directory. Then run:
pip install rls-persona-tester
rls-test -c demo_config.jsonDownload the REST config template, fill in your model, users and expected scope, then check connectivity for free.
pip install 'rls-persona-tester[rest]'
rls-test --preflight -c your_model.json
rls-test -c your_model.jsonSave your completed config as your_model.json. Set RLS_TESTER_LICENSE_KEY in your environment before the live run. Never commit your licence key.
Live testing needs the required capacity, tenant setting, permissions and role-bound test users. REST authentication uses MSAL user sign-in.
Check the requirementsWith REST dependencies, your model config, valid user authentication and the licence secret configured:
# JUnit for the CI test report
rls-test -c your_model.json -f junit -o results.xml
# JSON for your own automation
rls-test -c your_model.json -f jsonPublish results.xml as a test report and let the non-zero process exit fail the test step. Don’t ignore errors or mark the step as allowed to fail.
Start with the same checking engine. Add a licence when you’re ready to test your own Power BI and Fabric semantic models.
The offline simulated demo and --preflight connectivity diagnostics. No card required.
| Included | Free | Licence |
|---|---|---|
| Offline simulated demo | ✓ | ✓ |
| Preflight diagnostics | ✓ | ✓ |
| Live tests against your models | — | ✓ |
| Licensed product updates | — | ✓ |
Everything in the free demo, plus live testing against your real models and updates.
Secure checkout via Polar
Billed annually in USD. Cancel renewal anytime.
Applicable taxes calculated at checkout.
Refund policy pending publication
RLS Persona Tester is built by Green Analytics Ltd, a UK company led by a BI engineer with more than a decade in Business Intelligence. Made for the gap between defining access and proving what a user actually sees.
Tabular Editor issue #1198 asked how to validate RLS configuration. Persona-level regression testing goes a step further: checking the data returned for each configured user, not only the presence of role rules.
Independent product. Not affiliated with Microsoft or Tabular Editor.
Requirements, data handling and the things worth knowing before you buy.
Ask the developerA model on Premium, PPU or Fabric capacity; the tenant setting “Dataset Execute Queries REST API” enabled; model Read and Build permissions; and a test user per role, assigned in the model’s Security settings. A Fabric trial covers the capacity requirement.
The REST connector uses MSAL user authentication. Run the free --preflight check before purchasing to diagnose connectivity and permissions. Impersonation may require elevated model permissions; use a controlled test setup and confirm the requirements for your tenant.
Yes. It’s a cross-platform Python CLI using HTTPS for the REST connector. It runs on macOS, Linux and Windows with Python 3.9 or newer. No Power BI Desktop or .NET installation is needed.
Yes — it emits console, JSON or JUnit results and a non-zero exit code on failed checks. Configure your pipeline to stop when the command fails.
The current REST connector uses user authentication. Microsoft’s Execute Queries API does not support service principals for RLS models, so fully unattended service-principal CI is not supported through this connector. XMLA-based testing is on the roadmap.
Queries run directly between the CLI on your machine or runner and your Microsoft tenant, using your authentication. Model data is not sent to Green Analytics Ltd. Licence validation uses your licence key, not your model data.
Test output can contain measure values and visible dimension members. Treat local results and CI artefacts as sensitive and restrict access accordingly.
Payments are handled by Polar as merchant of record. We never see your card details. Polar handles applicable VAT and sales taxes at checkout.
The refund policy has not been published yet. Please contact Green Analytics Ltd before purchasing to confirm the applicable terms. No refund period or guarantee is implied.
An XMLA connector to activate roles by name and support unattended CI at scale; a sempy notebook connector for Direct Lake-native impersonation; and richer reporting and CI integration.
These are planned capabilities, not features included in the current release. Buy based on what the tool does today.
Not an incident. Not a customer email. A test you can fix before release.