Amberhold

Enterprise

Power BI, Excel and Fabric. Connected with your own Microsoft identity.

Your reporting tools read the plant's evidence on a schedule, with nobody at a keyboard — authenticated by Microsoft Entra ID from your own tenant, read-only, fully audited, and revocable by you at any moment. Amberhold never holds a credential of yours.

What IT and security will check first

Microsoft Entra ID · SSO · MFA · Conditional Access

People sign in with your work accounts and your own Conditional Access and MFA policies apply unchanged. Systems authenticate as Entra applications — OAuth 2.0 client credentials, no shared logins, no local accounts, no passwords held here.

Read-only · least privilege · no write path

A connected system holds the reporting role and nothing else. It cannot record, change or delete anything, and the database itself refuses to store a machine identity with any wider role — least privilege enforced by a constraint rather than by policy.

Revocation · kill switch · immediate effect

Revoke the membership in Amberhold and the next call is refused — on the next request, not when a token expires. Revoking consent in your Entra tenant stops new tokens being issued, so use the Amberhold side when you need it to stop immediately.

Audit trail · access logging · append-only

Every unattended read is written to an append-only access ledger: which system, which site, when, what scope, how many rows. The database rejects an update or a delete of that ledger, so the log cannot be edited after the fact.

Your secrets stay yours · UK hosting · export on demand

The client secret lives in your tenant — you create, rotate and revoke it, and Amberhold never sees or stores it. Data is hosted in the UK (London region) with daily backups and a rehearsed restore, and a site administrator can export the complete site record from inside the product at any time.

The shape of it

Your directory proves who. Your site decides what.

A system authenticates with an application identity from your own Microsoft Entra tenant — the same directory your people sign in from. That proves which system is calling. It grants nothing: until one of your site administrators registers that identity in Amberhold, a perfectly valid Microsoft token reads nothing at all.

Read-only, and not by policy — by construction

A registered system holds the reporting role and nothing else. There is no setting that would let it record a reading, change a round or alter a record, and the database itself refuses to store a machine identity with any other role.

We never hold your credential

The client secret belongs to the application in your tenant. You create it, you rotate it, you revoke it. Amberhold never sees it, never stores it and cannot leak it — which removes a whole category of question from a security review.

Two independent off switches

Yours

Withdraw the application's consent in your own Entra console, and no further tokens are issued to it. Nothing needs to be asked of us, and nothing of ours needs to change.

Ours

A site administrator presses Revoke on the Integrations screen. The next call is refused immediately — not when some token happens to expire. The same still-valid token that worked a minute earlier stops working.

Either switch is yours to throw without a support ticket — the answer to the question every IT review ends on. They act at different moments, and it is worth knowing which is which: withdrawing consent stops new tokens being issued, while Revoke here refuses the very next call. When you need it to stop now, use Revoke.

What you can see afterwards

Every unattended read is on the record

Which system, by the name you gave it; which site; when; what it asked for; and how many rows it received. Written to an append-only ledger — the database rejects an update or a delete of it.

One refresh reads as one pull

A reporting tool that needs nine requests to page through a month is one pull in your access log, because that is what happened. Nine entries labelled ‘export’ would be technically true and would misrepresent your plant.

Revoked systems stay listed

‘Which systems could read our evidence last quarter’ is a question worth being able to answer, so a revoked integration keeps its row, with who revoked it and when.

What it takes to set up

Three steps in your tenant, one in Amberhold

Your administrator consents to the Amberhold Machine Access application, registers the system that will read, and grants it the Readings.Read.All role. Then they send two identifiers — neither of them secret — and one of your site administrators registers it. Roughly twenty minutes, once per organisation rather than once per tool.

The same door for every consumer

Power BI, Microsoft Fabric, Excel, Power Automate, Logic Apps, SharePoint reporting, and your own software or CMMS all arrive the same way and read the same versioned projection through a REST API. Nothing bespoke is written for any of them, which is why adding the next one is a recipe rather than a project.

Walked end to end on production: a Microsoft service principal read a live site's evidence with nobody signed in, the access log recorded one attributable pull, and revoking the membership refused the very next call with the same valid token. What has and has not been walked for each specific tool is listed in the product, on the Integrations screen, rather than asserted here.

A question this page didn't answer?

Ask it directly — supplier questionnaires and security reviews are answered promptly, by the people who built the platform.