Microsoft Fabric & Azure · Governed data platforms · Infrastructure operations

Every number in your report, traceable to the system that produced it.

Control Shift Cloud builds governed Microsoft Fabric and Azure platforms for the organizations that run physical infrastructure — rail and freight, water and wastewater, transit, and airports. From sensors and operational systems through to certified models and regulatory reports.

Fabric · OneLake · Purview · Azure AI Foundry · Real-Time Intelligence · Power BI

Lineage — reported valueVerified to source
Discharge monitoring report · total suspended solids14.2mg/L · monthly average
Goldgold.discharge_daily_avg
certified semantic model · owner: compliance · refreshed 04:12
Silversilver.effluent_readings_clean
outliers flagged, units normalised, 6 rows quarantined
Bronzebronze.scada_historian_raw
ingested 00:05 · watermark 2026-07-27T23:59:59Z
SourceAnalyser TSS-114 · outfall 002
last calibration 2026-06-30 · tag OUT002.TSS.AVG
This is the deliverable. When a regulator or an auditor asks where a number came from, you open the lineage and answer in one screen.
Who it's for

Built for the teams that keep operations running.

Organizations that run assets in the physical world, report to a regulator, and have a small technology team carrying more than it should.

01

Rail & freight

Yard moves, car events, service performance, equipment utilisation, and the daily numbers operations actually runs on.

02

Water & wastewater

SCADA and historian data, discharge monitoring reports, asset condition, and the compliance submissions that can't be late.

03

Transit & transportation

Ridership, fleet availability, on-time performance, and federal reporting assembled from systems that don't talk.

04

Airports

Operations and gate use, parking and concession revenue, and board reporting that currently lives in a spreadsheet.

What we usually walk into

The reporting works. Nobody can prove it.

Reports assembled by hand

The monthly regulatory submission is built in Excel from four systems, every month, by one person who knows the steps and hasn't written them down.

Numbers nobody can defend

Two reports disagree. There's no way to say which one is right, where either came from, or what changed between last month and this one.

Telemetry locked in the historian

Years of SCADA and sensor data sitting in a system three people can query, none of whom work in the department that needs it.

Fabric bought, not used

Capacity is provisioned, licences are paid for, a workspace exists. Very little has actually moved into it, and the bill is climbing anyway.

Knowledge walking out the door

The person who built the reporting is retiring in eighteen months. Everything they know about why the numbers are calculated that way goes with them.

Platform coverage

One Microsoft estate. Built on Azure, governed end to end.

Fabric is where the work lands, but the platform underneath it is Azure — identity, networking, security and cost all live there. We work across the whole estate rather than one workload in isolation.

Foundation

Azure

  • Entra ID & managed identities
  • Key Vault & secrets
  • Private endpoints & VNet
  • Azure Data Factory
  • Azure SQL & Cosmos DB
  • Landing zone & FinOps
Data platform

Microsoft Fabric

  • OneLake & shortcuts
  • Lakehouse & Warehouse
  • Data Engineering (PySpark)
  • Data Factory pipelines
  • Real-Time Intelligence
  • Mirroring & Fabric Databases
Governance

Purview & catalog

  • Microsoft Purview integration
  • OneLake catalog & domains
  • Column-level lineage
  • Sensitivity labels & DLP
  • OneLake security, RLS & OLS
  • Certified & endorsed items
Intelligence

Fabric IQ & agents

  • Semantic models & DAX
  • Ontology & knowledge graph
  • Fabric data agents
  • Copilot in Fabric & Power BI
  • Microsoft Foundry grounding
  • Data Activator & operations agents

We build the governed foundation that AI workloads run on — semantic models, ontologies, catalogued and permissioned data. We don't train machine learning models or build custom applications, and we'll integrate cleanly with the team that does.

What we build

The governed platform behind every trusted report.

Reporting is the last ten percent. Underneath sits ingestion, a governed lakehouse, a certified semantic layer, an access model and a capacity budget. That's the part that decides whether the numbers hold up in three years.

Reference architecture · Microsoft Fabric on Azure Governed end to end
SOURCES SCADA historian ERP / finance Asset & maintenance Files, APIs, IoT INGEST Data Factory pipelines Eventstream real-time Mirroring ONELAKE Bronze — raw, immutable watermarked, replayable Silver — cleansed, conformed quality rules, quarantine Gold — business model certified, owned SERVE Semantic model DAX · RLS / OLS endorsed: certified Warehouse / SQL Data Activator alerting CONSUME Power BI paginated reports Excel Regulatory files DMR · NTD · board Copilot & data agents GOVERNANCE — MICROSOFT PURVIEW + ONELAKE CATALOG Column-level lineage Domains & ownership Sensitivity labels & DLP RLS / OLS access model Audit trail FOUNDATION — MICROSOFT AZURE Entra ID & managed identity Key Vault Private endpoints & VNet Capacity & FinOps CI/CD
Illustrative reference architecture. Platform engagements begin with a documented target architecture and delivery roadmap, sized to your sources, capacity and access model.
Purview · catalog entry Certified
DATA PRODUCTgold.discharge_daily_avg
DOMAINWater Operations
OWNERCompliance Manager
ENDORSEMENTCertified
SENSITIVITYConfidential — Regulatory
ACCESSRLS by plant · OLS on cost
LINEAGE4 upstream · 3 downstream
SLAdaily 04:00 · met 31/31
LAST SCANpassed · 0 issues
Illustrative sample. Governance is a deliverable, not a slide — every gold table gets an owner, a label and a documented access model.
Fabric capacity · F64 · last 24h No throttling
Capacity unit consumption vs limit THROTTLE THRESHOLD
PEAK CU71% of F64
THROTTLING EVENTS0
TOP WORKLOADSpark — nightly silver build
FORECASTF64 sufficient to Q2
Illustrative Fabric operating view. We size the capacity, schedule the workloads, and flag a bigger SKU before you need it — not after the bill arrives.
AI readiness

An agent inherits every problem your data already has.

Organizations are pointing Copilot and agents at warehouses where nobody agreed what "revenue" or "downtime" means, ownership is undocumented, and permissions are inconsistent. The agent doesn't fail loudly. It answers confidently, and it's wrong — which is worse.

Microsoft's own answer to this is Fabric IQ: a semantic layer over OneLake that gives agents business entities, relationships and rules instead of raw tables — and inherits Fabric's security and governance while doing it.

The governed platform and the AI platform are now the same platform.
Ontology · business entities an agent can reason over Grounded in governed data
operatesholds monitored_bylimits measured_atreported_in evidences Plant 14 instances Outfall 31 instances Permit NPDES · 6 parameters Analyser calibration state Sample time series Compliance report regulated output EACH ENTITY MAPS TO A CERTIFIED GOLD TABLE Agent answers inherit the same lineage, ownership, sensitivity labels and row-level security as the report — no separate AI permission model.
Illustrative ontology. Business entities and relationships an agent reasons over, instead of guessing from table and column names.
Foundation

Semantic models & ontology

Agreed definitions, entities and relationships — built once, reused by reports, Copilot, data agents and anything downstream. Ontologies can be generated from semantic models you already run.

Security

Agents inherit your access model

Row-level and object-level security travel with the answer. An agent shows a plant manager their plant and nobody else's — because governance is the boundary, not a separate AI policy.

Agents

Grounded, not guessing

Fabric data agents and Microsoft Foundry grounded on your certified layer. Consistent answers across Copilot, Teams and custom agents rather than a different number in every tool.

Operations

Real-time & acting on it

Eventstreams, Real-Time Intelligence and Data Activator for the operational edge — permit excursions, asset thresholds, service exceptions detected and acted on as they happen.

We make your estate AI-ready. We don't train custom models or build agent front-ends — we build the governed semantic foundation those depend on, and we'll work alongside whoever owns the model layer.

What the platform produces

The reports are the visible outcome.

Built on the certified semantic layer above — refreshed on a schedule, traceable to source, with an owner's name on every one. One platform, four different regulators.

Network operations · week 30 · terminal performance Certified · refreshed 05:40
Terminal dwell24.6hrs · target 22.0
Cars on line8,412−3.1% vs prior week
Trip plan compliance82.4%+1.8 pts
Locos out of service376 beyond 72 hrs
Train velocity — 13 weeks (mph) PLAN 21.5
Actual velocityOperating plan
Dwell by yard
YardDwellCarsStatus
Yard A21.41,840On plan
Yard B23.81,412On plan
Yard C27.91,196Watch
Yard D31.2968Over
Illustrative sample. Synthetic data, real metric definitions — built to show structure and governance, not client work.
What's included

Architecture, engineering, BI and governance from one team.

You don't have to hire four roles to ship one report. Everything below is covered by the subscription.

Platform

Lakehouse & pipeline build

Medallion architecture, batch and streaming ingestion, orchestration, notebook design, and recovery that handles a failed overnight run without a phone call.

Reporting

Semantic models & Power BI

Dimensional models, DAX, certified datasets, and reports your team can extend without breaking what's underneath.

Compliance

Regulatory reporting

Discharge monitoring, federal transit reporting, board packs and audit submissions — produced from the platform instead of rebuilt each period.

Governance

Lineage & access control

Column-level lineage, data ownership, row-level and object-level security, and a documented access model that survives an audit.

Integration

Historian & operational systems

SCADA historians, ERP, maintenance and asset management systems brought into one governed layer without ripping anything out.

Cost

Capacity management

Capacity sizing, throttling diagnosis, and workload scheduling so the Fabric and Azure bill matches what you're actually using.

How it works

Three practical stages. No unnecessary ceremony.

STAGE 01

Assessment

Four weeks, fixed price. We map your sources, size the capacity, and write the architecture and governance plan. You keep the document whether or not you continue — take it to procurement, to your board, or to another firm.

STAGE 02

Build

The subscription starts. Your backlog stays in your own Azure DevOps or Jira. We pull one item at a time from the top, build it, and ship it back with a committed date. You change priority whenever you like.

STAGE 03

Handover

Everything is built in your tenant, in your repos, documented as we go. When your team is ready to run it without us, they can.

Pricing

Published rates. No timesheets.

A subscription costs less than one full-time hire and covers the whole lifecycle.

Start here
$18,000
fixed · 4 weeks

Platform assessment. The fastest way to find out whether we're any good before committing to anything ongoing.

  • Source and system inventory
  • Target architecture & governance model
  • Fabric and Azure capacity sizing with cost forecast
  • Prioritised delivery backlog
  • Written report you own outright
Scope an assessment
Most common
$7,500
per month · one active lane

Ongoing delivery against your backlog. One item in active development at a time, next one starts the moment it enters testing.

  • Unlimited backlog items and re-prioritisation
  • Committed date on every active item
  • Architecture, engineering, BI and governance
  • Async by default — no standing status calls
  • Month to month. Pause or cancel any time
Book a 30-minute call
Higher throughput
$12,500
per month · two active lanes

For a live migration or a compliance deadline, where two workstreams need to move in parallel.

  • Two items in active development at once
  • Named architect across both lanes
  • Everything in the single-lane plan
  • Step back down to one lane any month
Talk through scope

Assessment scope is confirmed in writing at kickoff. Delivery timelines begin once access, source availability and acceptance criteria are agreed. Public sector buyers: we can structure the assessment as a fixed-scope professional services engagement on a purchase order.

Where we're not the right fit

Worth knowing before you book a call.

You're not on Microsoft. If your platform is Snowflake, Databricks-native, AWS or GCP, we're the wrong firm and we'll say so on the call.

You want staff augmentation. We don't sell seats by the hour or place contractors into your team.

You need 24/7 production on-call. We build and hand over. Round-the-clock operational support is a different service.

You want custom ML models or an application built. We build the governed data foundation AI runs on, not the models or the front end.

Why this company exists
Vijay N, founder and principal data architect at Control Shift Cloud
Vijay N
Founder & Principal Data Architect

I started Control Shift Cloud because I kept watching organizations buy excellent technology and still not trust their own numbers.

Most of my career has been inside operational businesses — transportation, logistics, industrial — where one report drives a dispatch decision, a regulatory filing, or a revenue figure somebody has to defend in a room. The technology was almost never the hard part. The hard part was building something people could actually rely on: where every figure can be explained, every transformation traced, and every answer holds up when someone senior asks where it came from.

The same pattern repeated everywhere I went. Millions spent on the platform, and the month-end number still assembled by hand in a spreadsheet, by one person who knew the steps and hadn't written them down.

Technology wasn't what was missing. Ownership was.

So the company is built around a single idea: if a number matters enough to run your business on, it should be possible to say exactly where it came from. That's why the work is Fabric, Azure, Purview, lineage and information architecture — not because those are fashionable, but because they're what governed actually requires.

I design every architecture. I review every implementation. I'm still the one working the problem when a pipeline fails overnight. That is how I intend to keep it.

Microsoft FabricAzure data engineeringInformation architecture Microsoft PurviewPower BI & semantic modelsGovernance & lineage

Every engagement starts with me. Every architecture is reviewed by me.

FAQ

Questions we get asked.

Are you Microsoft-only?

Yes. Fabric, Power BI, Purview and Azure, and nothing else. If your platform is built around Snowflake, Databricks or the AWS and GCP native stacks, another firm will serve you better and we'll tell you that on the first call. Narrowing to one estate is what lets a small practice cover architecture, engineering, BI and governance properly.

Do you take short-term Microsoft Fabric projects?

Yes. The four-week platform assessment is a fixed-price short engagement in its own right, and the subscription is month to month with no minimum term. If you have a single Fabric migration, a capacity problem, or one semantic model that needs building properly, that is a perfectly normal way to start.

What turnaround should we expect?

Every item gets a committed date the moment it enters active development. Small changes — a measure, a report tweak, a pipeline adjustment — usually ship within a day or two. Onboarding a new source or extending the engineering layer is typically a few days. A net-new dimensional or semantic model runs one to two weeks. Turnaround begins once requirements, access, source availability and acceptance criteria are confirmed.

How does "one item at a time" actually work?

Your backlog can hold as many items as you like. Only one is in active development at any moment. As soon as it moves to testing, the next one starts, so there's no idle gap — but nothing sits half-finished across three parallel threads either. You control the order throughout and can reshuffle whenever priorities change.

How does async communication work in practice?

Requirements, questions, reviews and handoffs happen in your ticketing tool and over Teams. Calls happen when they move the work forward — kickoff, a design decision, an unblock. What doesn't happen is a standing weekly status meeting, because the hours that would go into it go into building instead.

Can public sector organizations buy this?

Yes. We can structure the assessment as a fixed-scope professional services engagement and work with your procurement team on purchase order, vendor registration, insurance, security and contracting requirements. Purchasing rules vary by entity, service classification and funding source, so tell us your threshold and who signs and we'll shape the engagement around them.

Who owns the work?

You do. Everything is built in your tenant, in your repositories, under your licences. Documentation is written as we go rather than assembled at the end. If you cancel, you keep every artifact and nothing stops working.

What happens to our data, and who can access it?

Your data stays in your tenant. We work under your access controls with least-privilege accounts you provision and can revoke at any time. We'll sign your NDA and data processing agreement and complete your security questionnaire before anyone is granted access.

Can we pause or cancel?

Both, any month, with no termination fee and no minimum term. If the backlog goes quiet, pause billing and pick it up when it fills again — there's no re-onboarding charge.

What isn't included?

Custom machine learning model development, front-end application build, and 24/7 production on-call. We build the governed data foundation that AI and applications run on, and integrate cleanly with whoever handles the rest.

How do we get started?

Book a 30-minute call. If it's a fit, we'll scope the assessment, agree a start date, and you'll have the report four weeks later. If you already know what you need, you can go straight to a subscription.

Book a call

Thirty minutes. No deck, no script.

Tell us what you're reporting today and what keeps breaking. You'll get an honest answer about whether we can help — including if the answer is no.