Power BI, Excel and Fabric. Connected with your own Microsoft identity.
Your reporting tools read the plant's evidence on a schedule, with nobody at a keyboard — authenticated by Microsoft Entra ID from your own tenant, read-only, fully audited, and revocable by you at any moment. Amberhold never holds a credential of yours.
What IT and security will check first
Microsoft Entra ID · SSO · MFA · Conditional Access
People sign in with your work accounts and your own Conditional Access and MFA policies apply unchanged. Systems authenticate as Entra applications — OAuth 2.0 client credentials, no shared logins, no local accounts, no passwords held here.
Read-only · least privilege · no write path
A connected system holds the reporting role and nothing else. It cannot record, change or delete anything, and the database itself refuses to store a machine identity with any wider role — least privilege enforced by a constraint rather than by policy.
Revocation · kill switch · immediate effect
Revoke the membership in Amberhold and the next call is refused — on the next request, not when a token expires. Revoking consent in your Entra tenant stops new tokens being issued, so use the Amberhold side when you need it to stop immediately.
Audit trail · access logging · append-only
Every unattended read is written to an append-only access ledger: which system, which site, when, what scope, how many rows. The database rejects an update or a delete of that ledger, so the log cannot be edited after the fact.
Your secrets stay yours · UK hosting · export on demand
The client secret lives in your tenant — you create, rotate and revoke it, and Amberhold never sees or stores it. Data is hosted in the UK (London region) with daily backups and a rehearsed restore, and a site administrator can export the complete site record from inside the product at any time.
The shape of it
Your directory proves who. Your site decides what.
A system authenticates with an application identity from your own Microsoft Entra tenant — the same directory your people sign in from. That proves which system is calling. It grants nothing: until one of your site administrators registers that identity in Amberhold, a perfectly valid Microsoft token reads nothing at all.
Read-only, and not by policy — by construction
A registered system holds the reporting role and nothing else. There is no setting that would let it record a reading, change a round or alter a record, and the database itself refuses to store a machine identity with any other role.
We never hold your credential
The client secret belongs to the application in your tenant. You create it, you rotate it, you revoke it. Amberhold never sees it, never stores it and cannot leak it — which removes a whole category of question from a security review.
Two independent off switches
Yours
Withdraw the application's consent in your own Entra console, and no further tokens are issued to it. Nothing needs to be asked of us, and nothing of ours needs to change.
Ours
A site administrator presses Revoke on the Integrations screen. The next call is refused immediately — not when some token happens to expire. The same still-valid token that worked a minute earlier stops working.
What you can see afterwards
Every unattended read is on the record
Which system, by the name you gave it; which site; when; what it asked for; and how many rows it received. Written to an append-only ledger — the database rejects an update or a delete of it.
One refresh reads as one pull
A reporting tool that needs nine requests to page through a month is one pull in your access log, because that is what happened. Nine entries labelled ‘export’ would be technically true and would misrepresent your plant.
Revoked systems stay listed
‘Which systems could read our evidence last quarter’ is a question worth being able to answer, so a revoked integration keeps its row, with who revoked it and when.
What it takes to set up
Three steps in your tenant, one in Amberhold
Your administrator consents to the Amberhold Machine Access application, registers the system that will read, and grants it the Readings.Read.All role. Then they send two identifiers — neither of them secret — and one of your site administrators registers it. Roughly twenty minutes, once per organisation rather than once per tool.
The same door for every consumer
Power BI, Microsoft Fabric, Excel, Power Automate, Logic Apps, SharePoint reporting, and your own software or CMMS all arrive the same way and read the same versioned projection through a REST API. Nothing bespoke is written for any of them, which is why adding the next one is a recipe rather than a project.
A question this page didn't answer?
Ask it directly — supplier questionnaires and security reviews are answered promptly, by the people who built the platform.