A medical device distributor needed customers to see their own device and test data with zero visibility into anyone else's. We built a multi-tenant Power BI platform on DirectQuery with Row Level Security enforced at the data model layer, live in production across their distributor network.
Talk to Us About Your BuildA medical device distribution and management company serving hospitals and diagnostic centers across multiple territories.
14-table PostgreSQL data model, Row Level Security, embedded reporting, dynamic per-customer branding.
Power BI, PostgreSQL, DirectQuery mode, Row Level Security.
Delivered. Built over three months, now live in production across the distributor network.
The distributor owns the platform, but each customer's data has to stay invisible to every other customer on it. That constraint shaped every decision that followed.
Device, test, territory, and lab data lived across 14 relational tables with no drill-through capability. There was no way to move from network-level totals to a single device's performance history.
Hospitals, labs, and diagnostic centers share one platform but can't see a competitor's device performance or test volumes. Isolation had to hold at the data model layer, not just the dashboard UI.
Every customer login needed its own logo and dynamic titles, dual time zone display for IST and UTC regions, and shareable access without a full Power BI license for every viewer.
Power BI on DirectQuery against a 14-table PostgreSQL data model, secured with Row Level Security down to the customer level.
We mapped the client's PostgreSQL database into Power BI's data modeling layer, defining the fact-and-dimension relationships across devices, tests, territories, and labs before building a single report. We used DirectQuery mode throughout, so every query hits the live database rather than an imported snapshot. From there we built the drill-through hierarchy: network, then territory, then laboratory, then a specific device's performance history.
We implemented Row Level Security with an Admin role that has unrestricted access, and a Customer role that's authenticated per account and scoped only to the devices, locations, and reports allocated to that customer. The isolation lives in the data model, not the dashboard, so it can't be worked around by editing a URL. Customer allocation, including per-customer logos, is modeled as data in the database and pulled at login.
Auto-refresh runs on both Power BI Desktop and Power BI Service, so the published dashboard stays current without manual intervention. In DirectQuery mode there's no import cache to go stale, but every query hits the database directly, so we tuned the refresh schedule to balance live accuracy against query load. We also added IST and UTC as selectable display options, with validation built into the time conversion logic so a timestamp reads the same regardless of which zone the user selects.
We added embedded reporting so the dashboard can be reached through authenticated, shareable URLs. A recipient follows the link, authenticates, and lands on their RLS-scoped view automatically, no separate Power BI workspace license required. The embedded experience matches the full Power BI interface for everything that customer is authorized to see.
We can walk you through how the RLS architecture connects to the database schema and how the DirectQuery model holds up at drill-through depth.
Partner with us to design, build, and scale digital solutions that drive better outcomes.
Global Tech Teams LLC, 525 Washington Blvd, Industrious at Newport Tower, Jersey City, NJ 07310, United States.
Let’s discuss your goals, workflows, and next steps in a focused consultation call.