Every number in your report, traceable to the system that produced it.
Control Shift Cloud builds governed Microsoft Fabric and Azure platforms for the organizations that run physical infrastructure — rail and freight, water and wastewater, transit, and airports. From sensors and operational systems through to certified models and regulatory reports.
Fabric · OneLake · Purview · Azure AI Foundry · Real-Time Intelligence · Power BI
Built for the teams that keep operations running.
Organizations that run assets in the physical world, report to a regulator, and have a small technology team carrying more than it should.
Rail & freight
Yard moves, car events, service performance, equipment utilisation, and the daily numbers operations actually runs on.
Water & wastewater
SCADA and historian data, discharge monitoring reports, asset condition, and the compliance submissions that can't be late.
Transit & transportation
Ridership, fleet availability, on-time performance, and federal reporting assembled from systems that don't talk.
Airports
Operations and gate use, parking and concession revenue, and board reporting that currently lives in a spreadsheet.
The reporting works. Nobody can prove it.
Reports assembled by hand
The monthly regulatory submission is built in Excel from four systems, every month, by one person who knows the steps and hasn't written them down.
Numbers nobody can defend
Two reports disagree. There's no way to say which one is right, where either came from, or what changed between last month and this one.
Telemetry locked in the historian
Years of SCADA and sensor data sitting in a system three people can query, none of whom work in the department that needs it.
Fabric bought, not used
Capacity is provisioned, licences are paid for, a workspace exists. Very little has actually moved into it, and the bill is climbing anyway.
Knowledge walking out the door
The person who built the reporting is retiring in eighteen months. Everything they know about why the numbers are calculated that way goes with them.
One Microsoft estate. Built on Azure, governed end to end.
Fabric is where the work lands, but the platform underneath it is Azure — identity, networking, security and cost all live there. We work across the whole estate rather than one workload in isolation.
Azure
- Entra ID & managed identities
- Key Vault & secrets
- Private endpoints & VNet
- Azure Data Factory
- Azure SQL & Cosmos DB
- Landing zone & FinOps
Microsoft Fabric
- OneLake & shortcuts
- Lakehouse & Warehouse
- Data Engineering (PySpark)
- Data Factory pipelines
- Real-Time Intelligence
- Mirroring & Fabric Databases
Purview & catalog
- Microsoft Purview integration
- OneLake catalog & domains
- Column-level lineage
- Sensitivity labels & DLP
- OneLake security, RLS & OLS
- Certified & endorsed items
Fabric IQ & agents
- Semantic models & DAX
- Ontology & knowledge graph
- Fabric data agents
- Copilot in Fabric & Power BI
- Microsoft Foundry grounding
- Data Activator & operations agents
We build the governed foundation that AI workloads run on — semantic models, ontologies, catalogued and permissioned data. We don't train machine learning models or build custom applications, and we'll integrate cleanly with the team that does.
The governed platform behind every trusted report.
Reporting is the last ten percent. Underneath sits ingestion, a governed lakehouse, a certified semantic layer, an access model and a capacity budget. That's the part that decides whether the numbers hold up in three years.
An agent inherits every problem your data already has.
Organizations are pointing Copilot and agents at warehouses where nobody agreed what "revenue" or "downtime" means, ownership is undocumented, and permissions are inconsistent. The agent doesn't fail loudly. It answers confidently, and it's wrong — which is worse.
Microsoft's own answer to this is Fabric IQ: a semantic layer over OneLake that gives agents business entities, relationships and rules instead of raw tables — and inherits Fabric's security and governance while doing it.
The governed platform and the AI platform are now the same platform.Semantic models & ontology
Agreed definitions, entities and relationships — built once, reused by reports, Copilot, data agents and anything downstream. Ontologies can be generated from semantic models you already run.
Agents inherit your access model
Row-level and object-level security travel with the answer. An agent shows a plant manager their plant and nobody else's — because governance is the boundary, not a separate AI policy.
Grounded, not guessing
Fabric data agents and Microsoft Foundry grounded on your certified layer. Consistent answers across Copilot, Teams and custom agents rather than a different number in every tool.
Real-time & acting on it
Eventstreams, Real-Time Intelligence and Data Activator for the operational edge — permit excursions, asset thresholds, service exceptions detected and acted on as they happen.
We make your estate AI-ready. We don't train custom models or build agent front-ends — we build the governed semantic foundation those depend on, and we'll work alongside whoever owns the model layer.
The reports are the visible outcome.
Built on the certified semantic layer above — refreshed on a schedule, traceable to source, with an owner's name on every one. One platform, four different regulators.
Architecture, engineering, BI and governance from one team.
You don't have to hire four roles to ship one report. Everything below is covered by the subscription.
Lakehouse & pipeline build
Medallion architecture, batch and streaming ingestion, orchestration, notebook design, and recovery that handles a failed overnight run without a phone call.
Semantic models & Power BI
Dimensional models, DAX, certified datasets, and reports your team can extend without breaking what's underneath.
Regulatory reporting
Discharge monitoring, federal transit reporting, board packs and audit submissions — produced from the platform instead of rebuilt each period.
Lineage & access control
Column-level lineage, data ownership, row-level and object-level security, and a documented access model that survives an audit.
Historian & operational systems
SCADA historians, ERP, maintenance and asset management systems brought into one governed layer without ripping anything out.
Capacity management
Capacity sizing, throttling diagnosis, and workload scheduling so the Fabric and Azure bill matches what you're actually using.
Three practical stages. No unnecessary ceremony.
Assessment
Four weeks, fixed price. We map your sources, size the capacity, and write the architecture and governance plan. You keep the document whether or not you continue — take it to procurement, to your board, or to another firm.
Build
The subscription starts. Your backlog stays in your own Azure DevOps or Jira. We pull one item at a time from the top, build it, and ship it back with a committed date. You change priority whenever you like.
Handover
Everything is built in your tenant, in your repos, documented as we go. When your team is ready to run it without us, they can.
Published rates. No timesheets.
A subscription costs less than one full-time hire and covers the whole lifecycle.
Platform assessment. The fastest way to find out whether we're any good before committing to anything ongoing.
- Source and system inventory
- Target architecture & governance model
- Fabric and Azure capacity sizing with cost forecast
- Prioritised delivery backlog
- Written report you own outright
Ongoing delivery against your backlog. One item in active development at a time, next one starts the moment it enters testing.
- Unlimited backlog items and re-prioritisation
- Committed date on every active item
- Architecture, engineering, BI and governance
- Async by default — no standing status calls
- Month to month. Pause or cancel any time
For a live migration or a compliance deadline, where two workstreams need to move in parallel.
- Two items in active development at once
- Named architect across both lanes
- Everything in the single-lane plan
- Step back down to one lane any month
Assessment scope is confirmed in writing at kickoff. Delivery timelines begin once access, source availability and acceptance criteria are agreed. Public sector buyers: we can structure the assessment as a fixed-scope professional services engagement on a purchase order.
Worth knowing before you book a call.
You're not on Microsoft. If your platform is Snowflake, Databricks-native, AWS or GCP, we're the wrong firm and we'll say so on the call.
You want staff augmentation. We don't sell seats by the hour or place contractors into your team.
You need 24/7 production on-call. We build and hand over. Round-the-clock operational support is a different service.
You want custom ML models or an application built. We build the governed data foundation AI runs on, not the models or the front end.
I started Control Shift Cloud because I kept watching organizations buy excellent technology and still not trust their own numbers.
Most of my career has been inside operational businesses — transportation, logistics, industrial — where one report drives a dispatch decision, a regulatory filing, or a revenue figure somebody has to defend in a room. The technology was almost never the hard part. The hard part was building something people could actually rely on: where every figure can be explained, every transformation traced, and every answer holds up when someone senior asks where it came from.
The same pattern repeated everywhere I went. Millions spent on the platform, and the month-end number still assembled by hand in a spreadsheet, by one person who knew the steps and hadn't written them down.
Technology wasn't what was missing. Ownership was.
So the company is built around a single idea: if a number matters enough to run your business on, it should be possible to say exactly where it came from. That's why the work is Fabric, Azure, Purview, lineage and information architecture — not because those are fashionable, but because they're what governed actually requires.
I design every architecture. I review every implementation. I'm still the one working the problem when a pipeline fails overnight. That is how I intend to keep it.
Every engagement starts with me. Every architecture is reviewed by me.
Questions we get asked.
Are you Microsoft-only?
Yes. Fabric, Power BI, Purview and Azure, and nothing else. If your platform is built around Snowflake, Databricks or the AWS and GCP native stacks, another firm will serve you better and we'll tell you that on the first call. Narrowing to one estate is what lets a small practice cover architecture, engineering, BI and governance properly.
Do you take short-term Microsoft Fabric projects?
Yes. The four-week platform assessment is a fixed-price short engagement in its own right, and the subscription is month to month with no minimum term. If you have a single Fabric migration, a capacity problem, or one semantic model that needs building properly, that is a perfectly normal way to start.
What turnaround should we expect?
Every item gets a committed date the moment it enters active development. Small changes — a measure, a report tweak, a pipeline adjustment — usually ship within a day or two. Onboarding a new source or extending the engineering layer is typically a few days. A net-new dimensional or semantic model runs one to two weeks. Turnaround begins once requirements, access, source availability and acceptance criteria are confirmed.
How does "one item at a time" actually work?
Your backlog can hold as many items as you like. Only one is in active development at any moment. As soon as it moves to testing, the next one starts, so there's no idle gap — but nothing sits half-finished across three parallel threads either. You control the order throughout and can reshuffle whenever priorities change.
How does async communication work in practice?
Requirements, questions, reviews and handoffs happen in your ticketing tool and over Teams. Calls happen when they move the work forward — kickoff, a design decision, an unblock. What doesn't happen is a standing weekly status meeting, because the hours that would go into it go into building instead.
Can public sector organizations buy this?
Yes. We can structure the assessment as a fixed-scope professional services engagement and work with your procurement team on purchase order, vendor registration, insurance, security and contracting requirements. Purchasing rules vary by entity, service classification and funding source, so tell us your threshold and who signs and we'll shape the engagement around them.
Who owns the work?
You do. Everything is built in your tenant, in your repositories, under your licences. Documentation is written as we go rather than assembled at the end. If you cancel, you keep every artifact and nothing stops working.
What happens to our data, and who can access it?
Your data stays in your tenant. We work under your access controls with least-privilege accounts you provision and can revoke at any time. We'll sign your NDA and data processing agreement and complete your security questionnaire before anyone is granted access.
Can we pause or cancel?
Both, any month, with no termination fee and no minimum term. If the backlog goes quiet, pause billing and pick it up when it fills again — there's no re-onboarding charge.
What isn't included?
Custom machine learning model development, front-end application build, and 24/7 production on-call. We build the governed data foundation that AI and applications run on, and integrate cleanly with whoever handles the rest.
How do we get started?
Book a 30-minute call. If it's a fit, we'll scope the assessment, agree a start date, and you'll have the report four weeks later. If you already know what you need, you can go straight to a subscription.
Thirty minutes. No deck, no script.
Tell us what you're reporting today and what keeps breaking. You'll get an honest answer about whether we can help — including if the answer is no.