What problem does it solve? Fabric and Power BI tenant settings sprawl across dozens of toggles, delegated overrides, and security-group scopes, making it hard for administrators to know whether the live tenant posture matches governance intent or has drifted over time. ## Core Features & Use Cases - Baseline Drift Audit: Fetches live tenant settings via the fab CLI, merges them with a curated metadata baseline, and renders a markdown report with compliance status, risk levels, and change detection against the previous snapshot. - Delegated Override Enumeration: Enumerates capacity, domain, and workspace overrides and classifies each as drift-vs-tenant, drift-vs-recommended, high-risk, or orphan. - Security Group Investigation: Resolves Entra security groups referenced by settings via az CLI and Microsoft Graph, flagging empty groups, guest members, stale owners, and dynamic membership risks. - PDF Briefing: Generates a one-to-two-page stakeholder PDF with headline counts, changes since last audit, and the drift table. - Use Case: A Fabric admin runs a monthly governance review, detects that PublishToWeb was toggled on since the last snapshot, sees which security groups scope high-risk settings, and shares the PDF summary with stakeholders. ## Quick Start Ask the agent to run a tenant governance audit of my Fabric tenant settings and show any drift from the recommended baseline.