Skip to content

Certified versus ad hoc reports and the badge that tells readers which

BI and reportingUpdated 2026-08-237 min read

In short

A certified report has passed a named reviewer against published criteria and carries a badge saying so. An ad hoc report is exploratory work that anybody can build and share. Both are legitimate. The badge exists so a reader can tell in one glance which of the two is on the screen before quoting it.

Two exhibitor revenue figures turned up in the same Thursday meeting, eleven thousand pounds apart. Both came out of the same reporting tool. One was a finance-owned report reconciled to the ledger every month for three years. The other was something a commercial analyst had built in an afternoon to answer a question about sponsorship packages, and it was correct for that question.

Nobody in the room could tell which was which by looking. The certified versus ad hoc distinction exists to settle that, and it is smaller than a governance programme. Two tiers and a badge on the tile, applied consistently, does most of the work.

What the two tiers are actually for

The instinct when this happens is to reduce the number of reports. Delete the analyst's work, restrict who can publish, funnel everything through one team. That reaction kills the useful half of the workspace, because the afternoon report answered a real question faster than a request queue ever would.

The better move keeps both and labels them. Exploratory work stays cheap and fast. A small set of reports carries a visible mark saying that somebody has checked them against a standard, and readers learn what that mark means.

Microsoft's endorsement documentation (Microsoft Learn, 2026) implements exactly this shape and is worth reading even if your stack is somewhere else, because the boundary it draws is the right one. Items can receive one of three badges, promoted, certified or master data. Of promoted content the documentation says "Any user with write permissions on an item can promote it." Of certified content it says "only users specified by a Fabric administrator can actually certify items." One tier is self-service. The other is a gate with named keyholders.

The third badge, master data, marks an item as a core source of organisational data. In an event portfolio that is a small list: the show dimension, the exhibitor master, the golden attendee record. Most organisers can ignore it for the first year and use the two tiers.

How does a report earn a certified badge?

Four criteria carry most of the weight, and they are deliberately mechanical so that a review takes twenty minutes rather than a day.

A named owner who still works here. An individual, and a team mailbox does not count. The owner is who a reader emails when a number looks wrong, and who gets the review reminder.

Every measure documented. Each measure in the underlying model has a written definition, including the population filter and the time window. A reviewer should be able to read the definition and predict the number.

A refresh that has actually been succeeding. Not a refresh that is configured. A refresh history a reviewer can open, showing successful runs across a period long enough to include a show week, which is when refreshes break.

A review date in the future. Certification expires. A badge with no expiry is a badge that will still be there in four years when the owner has left and the measure means something else.

Microsoft's report consumer security planning guidance (Microsoft Learn, 2026) suggests a fifth criterion worth considering for anything holding commercially sensitive rows: it recommends deciding whether to require row-level security on semantic models before certifying them. For an exhibitions group where one director must never see a sibling brand's rate card, that requirement belongs in the list. The design of the filter itself is a separate subject and it sits with row-level security for event portfolios.

Working the audit on sixty reports

Run the criteria over an existing workspace and the funnel is bracing.

Sixty reports across nine shows. Start with the owner test: 22 have a named individual who is still at the company, so 38 fail on the first criterion, which is 63 per cent of the estate. That number alone usually ends the argument about whether an audit was needed.

Of the 22 survivors, 14 have every measure in the underlying model documented. Of those 14, nine have a refresh that succeeded on all thirty of its last scheduled runs. Of those nine, four have a review date set at all, let alone one in the future.

Four certified reports out of sixty is 6.7 per cent. That feels like a failure and it is close to the right answer. Four reports that a director can quote without checking is more useful than sixty reports of unknown standing, and the four are now a maintainable list.

The arithmetic of maintenance is what should set the ceiling. If certification lasts twelve months and each renewal costs a reviewer half a day including the conversation with the owner, forty certified reports is twenty reviewer days a year concentrated in whichever weeks are not show weeks. Certify more than your reviewers can re-review and the badge decays into decoration within two cycles.

What happens to the other fifty six?

They stay. This is the part teams get wrong, because an audit that produces a deletion list feels productive.

Most of the fifty six are fine. They are somebody's working view of a question that mattered for a fortnight. Leaving them alone costs a row in a list. The ones worth acting on are the ones being treated as certified without being certified, which you find by asking a different question: which of these has been screenshotted into a deck in the last quarter? That question is about usage and the measurement of it belongs to its own post, as does the separate discipline of retiring unused reports once the workspace is genuinely crowded.

For the middle tier, the promoted badge does real work. A report creator marking their own work as ready for reuse costs nothing and communicates something honest: this is finished, I stand behind it, no reviewer has looked at it. That is a different statement from certification and readers can hold both in their heads.

Who gets to be a reviewer

Certification is worth exactly as much as the standing of the people who grant it, and the two failure modes sit at opposite ends.

Appoint too many reviewers and certification becomes a formality that anybody can obtain by asking a friendly colleague. Appoint one and the queue becomes a bottleneck that people route around, which produces a workspace full of uncertified reports that everybody treats as authoritative anyway.

Two or three reviewers for a portfolio of nine shows works, drawn from finance and from the data team rather than from the show teams whose numbers are being reviewed. The Microsoft implementation allows certification to be delegated to domain administrators so a different reviewer set can be named per domain, which maps cleanly onto a group where the exhibitions business and the media business genuinely have different subject matter experts.

The reviewer group also needs the standing to say no, out loud, to a show director who wants their dashboard certified before a board meeting. If that cannot happen, the badge is already decorative and the audit will tell you nothing.

One practical detail decides whether reviewers stay willing. Give them a request form that makes the owner do the preparation: the four criteria as four fields, each answered before the request is submitted. A reviewer who has to chase an owner for a measure definition will approve the third request out of fatigue. A reviewer who opens a complete submission and spends the time on the one judgement that needs a human, which is whether the measure answers the question the report claims to answer, will keep doing it for years.

The refusals are also worth logging. Over a couple of cycles the reasons cluster, and the cluster tells you what to fix centrally. If eleven of fourteen refusals in a year came down to undocumented measures, the answer is a documentation pass on the shared model rather than more reviewer time. If they came down to refresh failures during show week, the answer is a gateway problem that has nothing to do with certification at all.

Where this stops

Certification says a report met a standard on a date. It says nothing about whether the standard was any good, and it says nothing at all about the source data.

A report can pass all four criteria and still be built on a badge scan feed with 60 per cent coverage, in which case the certified attendance figure is confidently and permanently wrong. Review catches modelling errors and abandoned ownership. It does not catch a measurement problem upstream, and a badge on a report built over bad collection makes that problem harder to challenge, because the reader now has a reason to stop asking.

The second limit is timing. Certification is a point-in-time judgement and the model underneath keeps moving. A measure definition can change the week after a review and the badge stays on the tile until the next cycle, which is why change control over definitions has to run alongside certification rather than inside it, and why versioning a measure when its definition changes is the companion discipline. Who can edit the model at all is a permissions question answered by workspace permissions for event teams.

The first step is an hour with the workspace list and one column. Open the reports your team publishes, and for each one write down the name of the person who would answer if a director emailed to say the number looks wrong. Count how many cells are empty or hold a name that has left. That count is the size of the problem, measured on your own reporting estate, and it is usually the only evidence needed to get the reviewer group appointed.

Questions people ask about certified versus ad hoc reports

What is the difference between a certified and an ad hoc report?
A certified report has been reviewed against written criteria by somebody authorised to do the review, and it carries a visible badge recording that. An ad hoc report is exploratory work built by anybody with access to the data. The difference is the review, and the badge is the only part of it a reader can see.
Who should be allowed to certify a report?
A small named group, appointed deliberately, holding enough context to judge whether a measure is right for the business rather than merely correct in the model. Two or three reviewers is usually enough for a portfolio of nine shows. The group needs the standing to refuse, which means it should sit outside the team that built the report.
How many reports should be certified?
As many as your reviewers can genuinely re-review on a schedule, which is a much smaller number than most teams expect. If every certified report is reviewed annually and one reviewer can handle a report a week around the show calendar, forty is already a full year of work. Scarcity is what makes the badge mean something.

Related reading

All bi and reporting articles