Fabric Implementation Guide · Part 2 of 10

Governance & Domain Workspace Design

Structure domain boundaries, workspace environments, endorsement rules, Purview sensitivity labels, and lifecycle policies for enterprise scale.

Target Audience: Platform Leads, FinOps, and Governance Officers
Estimated Read Time: 11 min

01Domain & Workspace Architecture Boundaries

In Microsoft Fabric, workspaces serve as both operational boundaries and identity access containers. Workspaces must be organized by Domain, Data Product, and Environment (Dev, Test, Prod), rather than individual developer sandboxes or temporary project teams. Use Fabric Domains to group related workspaces and delegate administration to domain leads while maintaining central tenant policies.

Implementation & Verification Checklist

  • Adopt a standardized naming convention: [Domain]-[DataProduct]-[Environment] (e.g. Sales-Revenue-Prod)
  • Separate Development, Test, and Production into dedicated workspaces
  • Assign named business and technical owners for every workspace and item
  • Restrict workspace creation rights to governed platform automation or service desks

02Purview Catalog, Endorsement & Data Item Lifecycle

Promote data trust by establishing formal item endorsement rules (Promoted vs. Certified). Leverage Microsoft Purview Hub to track tenant-wide item lineage, sensitivity labels, and access requests. Establish automated decommissioning policies for un-used workspaces, orphaned notebooks, and dormant capacity allocations.

Implementation & Verification Checklist

  • Define explicit technical and business criteria required for 'Certified' item endorsement
  • Map Purview sensitivity labels to prevent unauthorized export of sensitive metrics
  • Perform quarterly access reviews over workspace Admin, Member, Contributor, and Viewer roles
  • Automate alerts for un-assigned or orphaned workspace artifacts