Manual de Administração e Operação
Versão do manual
1.12.0
Aplica-se à versão Klarun
2026.09
Última atualização
24 de setembro de 2026
Klarun Documentation

Documentation

Everything you need to set up, configure, and use Klarun, your data team's operating system.

This documentation covers all six modules (Reporting, Governance, Platform, People, Projects, and FinOps), the 360 Assessment, Organization Settings, and the Roles system. Use the sidebar to jump to any section.

Get Started

What is Klarun

Klarun is a Data Ecosystem OS, a single platform that gives data leaders and their teams full operational visibility over every layer of their data organization: the reports they produce, the assets they govern, the people they manage, the platform they run, and the investments they make.

It is designed for CTOs, heads of data, and BI managers who need to operate at scale without the overhead of custom tooling. Rather than spreading context across Notion pages, spreadsheets, and disconnected BI portals, Klarun centralizes it, and connects to the tools your team already uses (Power BI, Databricks) to pull live data automatically.

Klarun follows a hybrid input model: some data is imported automatically through integrations, while other data is registered manually by your team. Both types live in the same interface and can be enriched, tagged, and acted upon in the same way.

Module Summary

Klarun is organized into six modules. Each module covers a distinct area of your data operation.

ReportingOperational Cockpit · Report Catalog · Maturity Benchmark
Centralizes all reports, dashboards, and BI assets across your organization.
GovernanceObservability Hub · Assets · Data Quality · Contracts & Sources
Tracks data assets, quality issues, vendor contracts, and governance health.
PlatformArchitecture · Health · Assessment
Documents your data platform architecture, business domains, and operational health.
PeoplePeople Ops · Data Team · Onboarding
Registry of your data organization, workforce analytics, and onboarding library.
ProjectsPortfolio · Objectives · Key Results · Initiatives · ROI Evaluator
OKR framework and initiative tracking for your data strategy.
FinOpsCost Intelligence · Budget & Plan · Actual Cost
Plan and track data platform spending, budget vs. actuals, and cost by platform.

Starting with Klarun

Follow these steps when setting up Klarun for the first time. The order matters, because organization settings and integrations unlock data that later steps depend on.

01
Complete Organization Settings

Go to Settings → Organization. Fill in your organization name, industry, company size, fiscal year start month, and timezone. These values power FinOps reports and benchmark comparisons.

02
Verify your domain

Still in Settings → Organization, register your company email domain. Once verified, anyone with a matching email can join via an invite link, with no one-off codes required.

03
Invite your team

Go to Settings → Membership and generate an invite link. Choose multi-use (whole team), email, domain, or single-use types. Assign roles before or after members join.

04
Connect integrations

In Settings → Integrations, connect Power BI and / or Databricks. Once connected, Klarun syncs all reports and assets from those platforms automatically. Integrations require the Business plan or higher.

05
Populate Reporting

In Reporting → Report Catalog, your synced reports will appear immediately. Enrich them with Domain, Subdomain, Owner, and Schedule. Manually register any reports from other tools.

06
Build out People

In People → Data Team, add every member of your data organization. Complete profiles (role, squad, seniority, skills, and languages) to unlock People Ops workforce analytics.

07
Add onboarding resources

In People → Onboarding, upload documents, paste links, or write text notes in each of the eight onboarding sections. New joiners access everything from this page.

08
Register platform architecture

In Platform → Architecture, document your data layers and infrastructure components, and expand the Business Domains section at the top of that page to map your domains. In Platform → Health, add any ongoing incidents.

09
Set up Governance

Assets are synced from integrations. In Governance → Contracts & Sources, add your data source contracts and SLAs. In Governance → Data Quality, log active quality issues.

10
Configure FinOps

In FinOps → Budget & Plan, enter your budget per platform and category. In FinOps → Actual Cost, record actual monthly spending. Cost Intelligence then computes budget vs. actuals automatically.

11
Define Projects (OKRs)

In Projects → Objectives, create your strategic goals. Link Key Results to each objective, then create Initiatives (the concrete work items) on the Initiatives kanban.

Free Plan

Klarun offers a free plan that lets you get started without a credit card. It is designed for small teams exploring the platform or for organizations that primarily need the core Reporting module.

Free · $0 / month
  • 5 data-team seats
  • Core reporting module
  • Basic data governance
Not included: viewer seats, integrations, AI assessment, and activity analytics.
To unlock all modules (Reporting, Governance, Platform, People, Projects, and FinOps) plus Power BI and Databricks integrations, upgrade to the Business plan ($390 / month) or higher. AI features such as the 360 Assessment require the Corporate plan or higher. See the pricing page for a full comparison.
Module

Reporting

What it is

The Reporting module is the central registry for all reports, dashboards, and data products in your organization. It gives every stakeholder a single place to find what exists, who owns it, how often it refreshes, and where to open it. The Operational Cockpit sits on top of the catalog as a live summary of reporting activity and health.

Pages: Operational Cockpit, Report Catalog, Maturity Benchmark

What it can be used for
Operational overviewSee reporting activity, coverage, and health at a glance on the Operational Cockpit.
Report discoveryLet any stakeholder find reports across all BI tools from one search.
Ownership trackingKnow who is responsible for each report and who to contact for updates.
Refresh visibilitySurface report freshness (daily, hourly, or on demand) to consumers.
Catalog enrichmentTag reports with domains and subdomains to enable business-aligned filtering.
Maturity assessmentBenchmark your organization's reporting maturity across key dimensions.
How to fill it

Reports enter the catalog in two ways: automatic sync from connected integrations (Power BI, Databricks), or manual registration for any other tool.

Report Catalog fields

FieldDescription
Report NameDisplay name of the report or dashboard.
LinkURL that opens the report. Auto-filled from Power BI / Databricks sync.
DescriptionFree-text context: what the report shows, who it is for.
DomainTop-level business domain (e.g. Finance, Marketing). Manually set.
SubdomainSub-classification within the domain (e.g. Revenue, Attribution).
WorkspaceOrigin workspace. Auto-filled and locked when synced from a BI tool.
OwnerEmail address of the person responsible for this report.
ScheduleHow often the report refreshes (e.g. Daily, Hourly, On demand).
ToolBI tool used to build the report (e.g. Power BI, Looker, Metabase).
StatusActive · Pending Review · Maintenance · Deprecated.
TagsFree-form labels for search and filtering.
Sync note: When a report is imported from Power BI or Databricks, the fields Report Name, Link, Tool, and Workspace are locked and overwritten on each sync. All other fields (Domain, Subdomain, Owner, Schedule, Description, and Tags) remain editable and are preserved across syncs.
Access notes
reporting_adminCan register, edit, delete, and manage all reports. Access to integration sync.
reporting_contributorCan register, edit, and delete reports.
reporting_viewerRead-only. Can browse, search, and open reports.
Module

Governance

What it is

The Governance module provides a unified view of your data ecosystem's health: all platform assets, their quality status, and the contracts governing your data sources.

Pages: Observability Hub · Assets · Data Quality · Contracts & Sources

What it can be used for
Asset visibilitySee every report, semantic model, notebook, pipeline, and lakehouse in one place.
Health monitoringIdentify broken, orphaned, or stale assets before they impact consumers.
Quality trackingLog and resolve data quality issues with ownership and severity tracking.
Contract managementTrack SLAs, renewal dates, trust status, and criticality per data source.
Governance overviewDashboard KPIs showing total assets, health scores, and open quality issues.
How to fill it

Assets are populated automatically from Power BI and Databricks integrations, with no manual entry needed. They are enriched with health flags (broken, orphan, stale) computed from integration metadata. Because assets depend on integrations, the Observability Hub and Assets pages require the Business plan or higher.

Contracts & Sources are entered manually. Each contract represents a data source your organization depends on. Fill in the fields below to track obligations and risk.

Contract fields

FieldDescription
NameDisplay name for the data source or vendor contract.
Source NameThe underlying data source identifier.
DomainBusiness domain this source belongs to.
OwnerPerson accountable for this data source.
CriticalityLow · Medium · High · Critical. Business impact if this source fails.
TrustWatch · Stable · Deprecated. Reliability status.
Contract TierNone · Bronze · Silver · Gold. SLA tier agreed with the provider.
SLAExpected availability or delivery window (e.g. "99.5% uptime").
ClassificationInternal · External · Confidential. Data sensitivity level.
ConsumersNumber of downstream consumers of this source.

Quality issues are logged manually. Each issue captures the affected asset, description, severity, owner, and resolution status.

Access notes
governance_adminFull access. Can manage assets, create/edit/delete contracts and quality issues.
governance_contributorCan create and edit contracts and quality issues.
governance_viewerRead-only access to all governance pages.
Module

Platform

What it is

The Platform module is where you document the infrastructure your data team runs on and track its operational health. It covers architecture documentation, business domains, platform health, and a maturity assessment.

Pages: Architecture · Health · Assessment

What it can be used for
Architecture docsMaintain a living record of your data platform layers, tools, and infrastructure components.
Licence inventoryTrack licensed tools and AI assistants with seat counts, cost per seat, and rollout status.
Business domainsDefine the business domains your data is organized around and assign ownership.
Incident trackingLog platform incidents with severity, affected systems, and resolution timelines.
Status visibilityGive the whole organization a clear picture of current platform health.
Maturity assessmentScore your platform maturity to identify gaps and prioritize investment.
Onboarding aidNew data engineers can understand the full platform at a glance without tribal knowledge.
How to fill it

Architecture is an inventory, not a diagram. It is divided into fixed sections, one per layer of the stack, and you register each tool, system, or workload you run as an entry inside the section it belongs to.

Architecture sections

SectionWhat belongs here
Data SourcesUpstream systems that feed the platform
LanguagesWhat the team builds with
Cloud ProvidersWhere the platform runs
OrchestrationHow workflows are scheduled and managed
Data Processing / PipelinesHow data is transformed
StorageWhere raw and processed data lives
Lakehouse / WarehouseStructured, consumption-ready data
BI / AnalyticsHow the business consumes data
Governance & CatalogControl and visibility
AI & MLAdvanced data capabilities
AI Assistants & AgentsLicensed AI assistants and agents in use

Every entry captures more than a tool name. Fields are grouped so that each workload records who is accountable for it, how heavily it is used, what it costs, and how it is secured.

Field groupCaptures
OverviewThe tool or system itself: name, type, technology, and cloud provider.
Ownership & CriticalityAccountable owner, business criticality, environment, and lifecycle stage (in use, being retired, planned). The owner can be picked from the data team, so ownership stays correct when someone changes role; a squad or free text covers vendors and anyone outside the roster.
Scale & UsageHow heavily it is used: adoption level, volumes, refresh frequency, and skilled headcount.
Licensing & CostLicence model, seat or capacity counts, cost, and the renewal or contract end date. Planning estimates only.
Security & ComplianceData classification, PII exposure, and data residency. A source marked as containing PII must be classified Restricted / PII; the two cannot disagree.
NotesFree-text description of the role this component plays in the platform.
Cost fields are planning baselines. Licence counts and cost-per-seat entered here are estimates used to size the platform. Actual monthly spend is tracked separately in FinOps → Actual Cost, and the two are not reconciled automatically.

Business Domains are registered in the Business Domains section at the top of the Architecture page. Tick the domains your data is organized around, or add your own. Domains are referenced across Reporting, Governance, and People.

Health incidents are logged with a title, severity (P1 to P4), a category (availability, performance, freshness, data quality, access or cost), the affected service, description, and current status: Open, Investigating, Monitoring (fixed, watching) or Resolved. Update the status as the incident progresses; the first move out of Open is recorded as the acknowledgement time, which is what mean time to acknowledge is measured from. The affected service is chosen from the Architecture registry rather than typed, so renaming an entry keeps its incident history and two entries that share a name stay distinct. Picking one suggests a severity from that service's business criticality, which you can override. Every change of status, severity, assignee or service is appended to the incident's history, which is written by the platform and cannot be edited. Marking an incident Resolved requires resolution notes and a resolved time that is not earlier than the start time, because those two fields are what MTTR is calculated from. A P1 or P2 additionally requires a root cause category and either a preventive action or an explicit "no preventive action needed": those are the incidents most worth learning from and the ones most likely to be closed in a hurry.

Assessment is a guided maturity questionnaire. Answer the prompts to produce a platform maturity score and a set of recommended next steps.

Access notes
platform_adminFull access. Can create, edit, and delete architecture entries, business domains and incidents. Deleting an incident hides it everywhere but keeps the record, along with who removed it and when.
platform_contributorCan create and update architecture entries and incidents, but cannot delete either.
platform_viewerRead-only access to architecture and health pages.
Module

People

What it is

The People module is the hub for your data organization's human layer. It combines a team registry, workforce analytics through People Ops, and an onboarding resource library.

Pages: People Ops · Data Team · Onboarding

What it can be used for
Team registryMaintain a live directory of every data team member with skills, domains, and seniority.
Org chartVisualize the team hierarchy, grouped by seniority, with drill-down profile cards.
Workforce analyticsUnderstand team composition, skill coverage, seniority distribution, and domain ownership.
Critical skill alertsIdentify skills held by only one member, a key operational risk.
Onboarding libraryStore and share every resource a new data team joiner needs, organized by onboarding phase.
How to fill it

Data Team profile fields

FieldDescription
NameFull name of the team member.
EmailWork email. Unique within the organization.
Employee IDOptional HR identifier. Visible to People admins only.
RoleJob title, selected from the standard data role list.
SquadTeam or chapter: Platform, AI / ML, Analytics, Governance.
SeniorityTrainee · Junior · Mid · Senior · Lead · Management.
Reports toThe member's manager, chosen from the team. Builds the org chart.
StatusActive or Inactive.
DepartmentWider business department. Free text.
SkillsNamed skills with a proficiency level (1 Beginner → 5 Expert). Platforms and tools are skills too: list Fabric or Databricks here, with a level.
LanguagesSpoken languages, each with a proficiency level.
Domain OwnershipBusiness domains the member is responsible for.

People holds no salary or compensation. Pay is recorded only in FinOps, under Actual Cost.

Onboarding sections

The Onboarding page is organized into eight fixed sections. Admins populate each section with documents, links, or text content.

SectionGoalTypical content
AccessRemove all friction to startSystem access, repo access, credentials, VPN setup
Business ContextUnderstand why the data existsCompany overview, key domains, core KPIs, data use cases
Ways of WorkingHow things get doneDev workflow, sprint model, comms channels, Definition of Done
Data ArchitectureUnderstand the big pictureArchitecture diagrams, data flow, medallion strategy, key platforms
EngineeringHow to build thingsCoding standards, pipeline patterns, naming conventions, CI/CD
AnalyticsHow data is consumedBI standards, semantic models, metrics layer, report best practices
GovernanceRules and responsibilitiesData ownership, access control, quality expectations, compliance
AI & MLAdvanced capabilitiesML workflows, feature engineering, model deployment, experiment tracking

Resource types

DocumentUpload any file (PDF, DOCX, XLSX, etc.). Stored securely; a Download button appears on the card.
LinkPaste any URL (Confluence, Notion, YouTube, etc.). An Open button opens it in a new tab.
TextWrite plain text or Markdown directly in Klarun. Shown inline with a Show more / Show less toggle.
Themselves and their reports

An admin can narrow a member's People role to Themselves and their reports, in Settings → Membership under the People roles. The member then reads only their own team member record and everyone under it in the reporting line, directly or indirectly. Data Team shows how many of the whole team they are seeing, and the org chart starts at them.

WhereWhat a narrowed member gets
Data TeamTheir own record and their reports, including the owned-assets tab. Anyone else is answered as not found.
People OpsComposition, skills, and ramp for their own line. The risk register, domain coverage, and the estate describe the whole team, so they are locked.
ChangesAs a People admin: only records in their line. New members go under someone in that line, members in it keep a manager in it, their own manager is set by the people above them, and a member who still has reports cannot be deleted until those reports move.
ElsewhereThe Cockpit shows no People figures and the 360 Assessment no people section, since both describe the whole team. Pickers in other modules still list every member by name and status only.

The line starts from the team member record linked to the member's Klarun account. With no linked record, with two, or when the reporting line loops back to them, the member sees nobody, and Settings shows a warning next to them. Managers are checked on every change, so a new loop cannot be saved. The change applies on the member's next request and is recorded in the audit log. Organization admins are never narrowed.

Access notes
people_adminCan add, edit, and delete team members and onboarding resources. The only role that sees the Employee ID.
people_contributorSame read access as people_viewer. Adding, editing, and deleting team members and onboarding resources needs people_admin.
people_viewerRead-only access to profiles, org chart, People Ops analytics, and onboarding resources.
Module

Projects

What it is

The Projects module is Klarun's OKR (Objectives and Key Results) framework. It gives data teams a structured way to define their strategy, track measurable outcomes, and manage the concrete work items that deliver on those outcomes. The Portfolio gives a high-level view across all objectives and initiatives.

Pages: Portfolio · Objectives · Key Results · Initiatives · ROI Evaluator

What it can be used for
Portfolio viewSee every objective, key result, and initiative in one place to track strategy at a glance.
Strategic alignmentConnect day-to-day work to high-level business goals through a three-tier hierarchy.
Outcome trackingMeasure progress against Key Results with numeric targets and milestones.
Initiative kanbanManage work items (initiatives) on a kanban board linked to Key Results.
ROI measurementAttach financial impact estimates to initiatives to quantify data team contribution.
How to fill it

Start top-down: create Objectives first, then add Key Results to each one, and finally create Initiatives under Key Results.

ObjectiveTitle, description, owner, quarter, status (On Track / At Risk / Off Track / Done).
Key ResultTitle, linked objective, metric type (number, percentage, binary), start value, target value, current value, due date.
InitiativeTitle, description, linked key result, owner, priority, status, start and end dates, estimated and actual impact (for ROI).
Edit only what you own

An admin can narrow a member's Projects role to Only what they own, in Settings → Membership under the Projects roles. Reading does not change: the member still sees every objective, key result, and initiative, so the Portfolio and the progress roll-ups stay whole. What narrows is what they can change.

ItemThe member can change it when
ObjectiveThey are its owner. Objectives they create are theirs.
Key resultThey are its owner, or they own its objective. They add key results only under objectives they own, and log progress only on key results they own.
InitiativeThey are one of its data team owners, or it serves an objective they own. Initiatives they create list them among the owners.

An initiative's contributions move the progress of the key results it links. So a narrowed member cannot link, unlink, or change a contribution to a key result they do not own, even on an initiative they own. Those links stay as they are.

Ownership comes from the team member record linked to the member's Klarun account, and each account can be linked to one record only. With no linked record, or with two, the member can change nothing, and Settings shows a warning next to them. The change applies on the member's next request and is recorded in the audit log. Organization admins are never narrowed.

Access notes
projects_adminFull access. Can create, edit, and delete objectives, key results, and initiatives, or only the ones they own when an admin narrows them.
projects_contributorCan create and update objectives, key results, and initiatives, or only the ones they own when an admin narrows them. Deleting needs projects_admin.
projects_viewerRead-only access to all Projects pages.
Module

FinOps

What it is

The FinOps module gives data leadership the financial visibility they need to run the data function as a business. It covers budget planning, actual cost tracking, and a Cost Intelligence overview that compares the two.

Pages: Cost Intelligence · Budget & Plan · Actual Cost

What it can be used for
Cost intelligenceSee planned vs. actual spending per platform and category, month by month, on one overview.
Budget planningBuild out your data platform budget by tool and category for the fiscal year.
Actuals trackingRecord actual monthly spend, with AI-assisted entry from invoices and payroll on Corporate plans.
Variance analysisTrack budget vs. actual variance automatically and spot overruns early.
How to fill it

Budget & Plan: Add budget lines for each data platform (e.g. Databricks, Snowflake, Power BI) broken down by cost category and month. The fiscal year calendar is driven by your Organization Settings → Fiscal Year Start.

Actual Cost: Enter or import actual monthly spending for each platform and category. On Corporate plans and above, AI assist can parse uploaded invoices and payroll into structured monthly rows.

Cost Intelligence reads from your budget and actuals and computes variance automatically. No separate data entry is required on this page.

FinOps sections

FinOps data is split into three sections, each shared all-or-nothing on top of the FinOps role. The role sets how much a member can do in FinOps; the sections set which parts of it they see.

SectionWhat it covers
PlatformPlatform cost: budget and actuals per resource, and uploaded invoices.
Team (payroll)Squad budgets, team totals, and per-person payroll.
ProjectsProject budgets and initiative cost logs.

With nothing chosen, FinOps admins hold every section and everyone below admin holds Platform and Projects, so payroll is always an explicit grant. Organization admins always hold every section. An admin changes a member's sections in Settings → Membership, under the FinOps roles. The change applies on the member's next request and is recorded in the audit log.

Figures that add sections together, such as the combined budget and variance on Cost Intelligence and the FinOps figure on the Cockpit, appear only for members who hold both Platform and Team. Opening or deleting a fiscal year and changing the fiscal-year start need every section. The 360 Assessment shows its finance section only to members who hold every section.

Access notes
finops_adminCan create, edit, and delete budget lines, actuals, and project budgets in the sections they hold. Holds every section unless an admin narrows them.
finops_contributorSame read access as finops_viewer. Changing FinOps data needs finops_admin.
finops_viewerRead-only access to the FinOps sections they hold.
Intelligence

360 Assessment

What it is

The 360 Assessment is Klarun's AI-powered organizational review. It synthesizes data from across your modules (Governance, Platform, People, Projects, and FinOps) into a single, periodic assessment of your data organization's health, with narrative insights and recommendations.

Pages: 360° View

What it can be used for
Health overviewGet a synthesized, leadership-ready picture of your data organization across every module.
Period trackingGenerate an assessment per period and track how your organization evolves over time.
RecommendationsSurface AI-generated strengths, gaps, and recommended next steps.
CollaborationCapture comments and feedback on each assessment to align stakeholders.
How to fill it

There is no manual data entry. Keep the other modules up to date, then generate an assessment for a period. The quality of the result depends on how complete your Governance, Platform, People, Projects, and FinOps data is.

Access notes
intelligence_adminFull access. Can view assessments and generate new ones.
intelligence_contributorCan view assessments and generate new ones.
intelligence_viewerRead-only. Can view assessments and post comments and feedback.
Intelligence is its own permission module (the 360 Assessment is currently its only feature). Org-wide roles (org_admin, org_member, org_contributor, org_viewer) include Intelligence access at their tier. An assessment covers every module, but each reader sees only what their own roles allow: the finance section needs every FinOps section, initiative budgets and costs need the FinOps Projects section, and the people section needs People read. The 360 Assessment is also an AI feature available on the Corporate plan and above. On Free and Business plans it appears in the sidebar with an upgrade badge and is not accessible.
Configuration

Organization Settings

Settings are accessible from the sidebar under your organization name. The page is divided into four tabs: Organization, Integrations, Membership, and Billing. Users with the org_admin role can modify every setting. The org_member role can manage the Organization, Integrations, and Membership tabs, but not Billing, and cannot grant the admin role.

Organization tab

Configure your organization profile. These values appear throughout the app and power features like FinOps and benchmarking.

FieldDescription
NameYour organization's display name, shown throughout the app.
DescriptionShort description of your data team or organization.
IndustryYour company's industry sector. Used for benchmark comparisons.
SizeHeadcount range of the overall company (not just the data team).
WebsiteCompany website URL.
CountryCountry of the organization's headquarters.
TimezoneUsed to localize scheduled refresh times and reports.
Fiscal Year StartThe month your fiscal year begins. Affects FinOps period calculations.

Domain verification

Register your company email domain to enable domain-based invite codes. Anyone with a matching email address can then join your workspace using a domain invite link, without needing a one-off code.

Verification is done via a one-time code sent to an admin email on the registered domain. Once verified, the domain is locked and used for all future domain invites.

Integrations tab

Connect your BI tools to Klarun. Synced integrations automatically populate Reports (Reporting module) and Assets (Governance module).

Power BI setup steps

01
Create an Azure App Registration

Go to Azure Portal → Microsoft Entra ID → App registrations → New registration. Give it any name (e.g. "Klarun Integration"), select Single tenant, and click Register. Use a dedicated registration: do not reuse the one connected to Microsoft 365 Copilot.

02
Add no API permissions

Leave API permissions empty. Do not add Tenant.Read.All, and do not grant admin consent. Power BI refuses a service principal that carries admin-consented Power BI permissions in Entra, and the call then fails with a 401 that reads like a credential problem. Access is granted in the Power BI admin portal instead, in steps 03 and 04.

03
Allow service principals to call Power BI APIs

Open Power BI Admin Portal → Tenant settings → Developer settings. Enable "Service principals can call Fabric public APIs". This covers workspace and report listings. If you scope it to a security group, add the service principal to that group.

Power BI Admin Portal → Tenant settings → Developer settings → Service principals can call Fabric public APIs
04
Allow read-only admin API access

In the same portal, open Tenant settings → Admin API settings and enable "Service principals can access read-only admin APIs". This is a separate switch from step 03 and covers tenant-wide metadata, lineage and usage. Scope it to a group the service principal belongs to, then allow about 15 minutes for both settings to take effect.

Power BI Admin Portal → Tenant settings → Admin API settings → Service principals can access read-only admin APIs
05
Create a client secret

Back in the app registration → Certificates & secrets → New client secret. Set an expiry and click Add, then copy the Value column immediately. Do not copy the Secret ID, which sits beside it and is not a credential. The Value is shown only once.

06
Connect in Klarun

Go to Settings → Integrations → Power BI → Connect. Enter your Tenant ID, Application (Client) ID, and the Client Secret value. Click Test connection, and if successful, click Save & sync.

Why the admin API? The standard Power BI API only returns workspaces where the service principal is a direct member, which for a new registration is none. The admin API returns every workspace in the tenant, which is why step 04 is required rather than optional. The Fabric Administrator role is needed only if you enable “Auto-assign Viewer role to workspaces” when connecting, which lets sync read Lakehouse table metadata.

Databricks

Connect one or more Databricks workspaces using a personal access token and workspace URL. Once connected, Klarun syncs notebooks, pipelines, and ML assets as Governance assets and enriches the Report Catalog with Databricks-backed reports.

Membership tab

Manage who belongs to your Klarun workspace. You can view all current members, change their roles, and create invite codes.

Invite code types

TypeBehavior
Multi-useAnyone with the link can join. Expires after 30 days.
EmailOnly a specific email address can use this code.
DomainAnyone with an email from a specified domain can join.
Single-useOne person only. Expires after 7 days.

Billing tab

View your current plan and manage your subscription. Upgrading, downgrading, and entering payment details are all handled from this tab. Only users with the org_admin role can access the Billing tab.

Access control

Roles

Klarun uses a layered role system. Every member has one org-wide role that controls baseline access across the entire workspace, plus optional module-specific roles that grant elevated permissions within individual modules.

Org-wide roles

Assigned at the workspace level. Apply to all modules unless overridden by a module-specific role.

RoleDescription
org_adminFull access to all modules and all organization settings, including billing.
org_memberSecond-highest role. Full access to every module and can manage all organization settings except billing. Cannot grant the admin role.
org_contributorCan create and edit content across all modules. No organization settings access.
org_viewerRead-only access across the entire organization.
business_viewerFocused read-only view of the Reporting module (Report Catalog). For anything more, assign a specific module role.

Module-specific roles

Each module has three tiers: admin, contributor, and viewer. Module roles are additive: assigning a module role to a member grants that permission level for that module regardless of their org-wide role.

ModuleAdminContributorViewer
Reportingreporting_adminreporting_contributorreporting_viewer
Governancegovernance_admingovernance_contributorgovernance_viewer
Platformplatform_adminplatform_contributorplatform_viewer
Peoplepeople_adminpeople_contributorpeople_viewer
Projectsprojects_adminprojects_contributorprojects_viewer
FinOpsfinops_adminfinops_contributorfinops_viewer
Intelligenceintelligence_adminintelligence_contributorintelligence_viewer

Permission matrix

Baseline permissions by role tier, applicable across all modules. Module admins have the same privileges as org admins within their module scope. Exception: in People and FinOps, creating, editing, and deleting records needs the admin tier, and FinOps is further divided into sections (see FinOps sections). In Projects, an admin can limit a member to changing only what they own (see Edit only what you own), and in People to themselves and their reports (see Themselves and their reports). Anyone whose Klarun account is linked to a team member record can edit their own skills and languages.

ActionAdminContributorViewer
View all content✓✓✓
Create, edit, and delete records✓✓—
Manage organization settings✓——
Manage members and roles✓——
Manage integrations✓——
Generate and share invite links✓——
Roles are assigned from Settings → Membership. Select a member, click Edit roles, and choose from all available org-wide and module-specific roles. Changes take effect immediately on next page load.
Access control

Data Access Scopes

Roles decide what a member can do in each module. Data access scopes narrow which of that module's records they reach. A scope only ever narrows a role: it never grants access the role does not give, and organization admins are never scoped. Scopes belong to each member, are set by an admin in Settings → Membership next to the roles they narrow, and are enforced on the server on every request, for the pages and the API alike.

The three scopes

ModuleChoicesWith nothing chosen
FinOpsSections: Platform, Team (payroll), Projects. At least one.FinOps admins hold every section and everyone else holds Platform and Projects, so payroll is always an explicit grant.
ProjectsEverything their role allows, or Only what they own.Everything their role allows. Reading stays open either way: the scope narrows what they can change.
PeopleEveryone their role allows, or Themselves and their reports.Everyone their role allows.

Each scope is described in full with its module: see FinOps sections, Edit only what you own, and Themselves and their reports.

When a scope cannot be worked out

The Projects and People scopes start from the team member record linked to the member's Klarun account. Each account can be linked to one record only, and an admin can link a record to their own account only when the record's e-mail is theirs. When the link is missing or doubled, or when the reporting line loops back to the member, the scope gives nothing rather than guessing: in Projects the member can change nothing, and in People they see nobody. Settings shows a warning next to the member so an admin can fix the record. Managers are checked on every change, so a new loop cannot be saved. A stored scope that cannot be read is treated as the narrow choice.

Everywhere the data appears

A scope follows the data rather than the page, so the same rules apply wherever that data is shown.

SurfaceWhat a scope changes
Operational CockpitThe FinOps figure adds only the sections the member holds and says which one it is. People figures are hidden from members who see only their reports.
360 AssessmentThe finance section needs every FinOps section, initiative budgets and costs need the Projects section, and the people section needs People access to the whole team.
Imports and AI data entryBudget and actuals uploads, invoice and payroll parsing, and AI-assisted entry each need the section they write to, checked before any file is read or any AI budget is spent.
Pickers in other modulesList every team member by name and status only, so objectives and initiatives can be assigned. No other People data is included.

Audit

Every scope change is recorded as admin.scope_changed, naming the member, the admin, and the new value for each module it touched. Every change to the account a team member record is linked to is recorded as people.link_changed, and role changes remain admin.role_changed. A scope change applies on the member's next request without signing them out; a role change signs them out of every session, so it applies at once. Admins who manage Settings can read the audit trail.