Microsoft Fabric has unified data ingestion, data engineering, data science, and analytics into a single platform. However, many of the decisions that rely on that data are still made outside of it—in spreadsheets, emails, and departmental applications—which duplicate information and make traceability difficult.
Fabric Apps and Rayfin bridge that final gap. They enable the development and deployment of business applications within Fabric—directly connected to lakehouses, data warehouses, and semantic models, and secured with Microsoft Entra ID corporate identity. In this way, the data platform evolves from being solely an analytics environment to supporting the organization’s operational processes.
In our blog, we’ve already discussed how Microsoft Fabric is changing the way companies work with data. In this article, we take the next step and focus on the application layer—what each component contributes, how it integrates with existing assets, and in which scenarios it generates business value.

What are Fabric Apps and Rayfin?
Fabric Apps is a feature of Microsoft Fabric—currently in preview—that provides the managed infrastructure required by an enterprise application. It combines an operational database, GraphQL APIs, authentication with Microsoft Entra ID, and front-end hosting into a single service, managed within Fabric and subject to allocated capacity and tenant configuration.
Rayfin is the TypeScript SDK used to develop these applications. The team describes business entities, their relationships, and their permissions using classes and decorators, and Rayfin uses these to generate the database schema, APIs, and type-safe clients consumed by the front end. Its CLI covers the entire lifecycle, from project creation and local development to deployment on Fabric.
This combination eliminates much of the infrastructure work that typically slows down these types of projects and allows the team to focus its efforts on the business process. Its main capabilities are as follows.
- Declarative data model. Entities in TypeScript define the application’s specific information, along with their relationships and access rules.
- Generated APIs and clients. Rayfin generates GraphQL APIs and type-safe clients from the model, without the need for a hand-coded data access layer.
- Corporate identity. Authentication with Microsoft Entra ID incorporates Fabric’s single sign-on without requiring the development of a custom identity system.
- Data connectors. They provide type-safe access to Lakehouse, Warehouse, and SQL databases on Fabric, as well as semantic models linked to user identity.
- Server logic. Rayfin Functions are server functions written in TypeScript that are deployed alongside the application. They validate operations, manage secrets, and call Fabric APIs or external services.
- Integrated hosting. The interface is deployed alongside the application’s services, with no additional infrastructure to provision.
Architecture of an Application on Fabric
The architecture distinguishes between two types of information. Analytical data remains in the Lakehouses, Warehouses, and semantic models already managed by the organization, and the application queries them via connectors without replicating them. Operational state, on the other hand—such as requests, scenario parameters, approvals, or references to executions—is modeled using Rayfin entities and stored in the application’s managed database.
Rayfin Functions connect both layers. When a user initiates an operation, the front end invokes it through the generated client, and the server-side code applies the business rules, uses the configured credentials, and coordinates the relevant Fabric services. The result is a single source of truth for data and business-logic that runs on the server, not in the browser.
What can you build with Fabric Apps and Rayfin?
Power BI, notebooks, and Data Agents already handle analysis, calculation, and natural language queries separately. What they don’t offer is a dedicated application that combines these capabilities into a business process, remembers the decisions made, and controls who can execute each action. That is where Rayfin comes in. From a single TypeScript project, the team defines the application’s state as entities, accesses Fabric data via type-safe connectors, and encapsulates sensitive operations in Rayfin Functions—without having to develop a separate backend, database, or authentication system.
The following scenarios describe, for each use case, the business need, what Rayfin offers compared to using Fabric’s tools separately, and how each component integrates.
Business Planning Based on the Semantic Model
A sales manager who detects a sales deviation in their region using Power BI can analyze it in the report, but the proposal to adjust targets usually ends up in an email or a spreadsheet, disconnected from the data that prompted it. With Rayfin, the analysis and the decision are part of the same application. The semantic model connector runs DAX queries on the metrics already maintained by the BI team, ensuring that the figures match those in Power BI without duplicating logic, and the proposal is saved as an entity with its author, status, and reference indicator, protected by the permissions defined in the model.
The front end combines custom charts powered by the connector with forms built on the entities’ type-safe client, and if the organization prefers to retain its reports, it can embed a Power BI report alongside those forms. The result is a structured record of decisions that a report alone cannot maintain.
On-demand forecast recalculation
Recalculating a forecast, simulating a scenario, or reprocessing a period typically requires a technical user to open Fabric and run a pipeline or a notebook, with no record of who requested the calculation or what parameters were used. Rayfin transforms this technical process into a controlled business operation. A Rayfin Function exposes the “recalculate scenario” action to the front end, verifies that the user is authorized and that the parameters fall within the allowed range, and launches the job via Fabric’s on-demand jobs API using credentials that never reach the browser. Since execution is asynchronous, the application logs each request as an entity along with the job identifier, allowing it to display progress, prevent duplicate runs, and retrieve the result via the connectors upon completion. Each figure is thus associated with the execution that produced it, without the need to build a separate audit system.
Proposal Approval with Controlled Writing
Processes such as budget validation or inventory adjustments require multiple people to review, comment on, and approve them before a change is reflected in corporate data, and Fabric does not natively offer an approval workflow for these processes. Rayfin allows you to model this workflow within the application. Entities represent the proposal, its comments, and its status; their permissions determine who can view, comment on, or approve each record; and a Rayfin Function applies transition rules, such as verifying that the proposal is still pending or that no one has modified it since it was reviewed. Once approved, the decision can be transferred to the corporate data via the Warehouse and SQL database connectors in Fabric, which support write operations when enabled; whereas in a Lakehouse—whose connector is read-only—writing is handled through a compatible process, such as a notebook launched from the application.
The workflow is thus governed and auditable within Fabric, without resorting to an external workflow tool.
Business-Driven Validation of Predictive Models
Data science teams train and evaluate their models in Fabric notebooks and log their experiments using MLflow, but the decision on which version to use in planning rests with the business, which does not work with those tools. Rayfin provides a validation console tailored to the business’s perspective. Connectors read the predictions and evaluation metrics that the notebook publishes to the Lakehouse or Warehouse; the application displays the error by product or region compared to actual values; and a system records which version is approved, who makes the decision, and with what comments. If the user requests a new evaluation, the application runs it as a job using the same mechanism as for recalculating forecasts.
Training remains in Fabric, and model approval ceases to be an informal agreement and becomes a traceable step in the MLOps cycle.
Conversational Analytics with Fabric Data Agents
Fabric Data Agents allow users to ask questions in natural language—for example, which locations account for a drop in demand—but using them in isolation requires switching tools and manually transferring context. When integrated into an application built with Rayfin, the agent becomes part of the process. The query is formulated from the view where the user analyzes the scenario; the application adds the context it already knows—such as the selected region or time period—and if the response requires action, the user recalculates or creates a proposal on the same screen.
In the integration, the published Data Agent is exposed as an MCP server, and a Rayfin Function acts as the client, managing authentication with Fabric and sending the query, as described by Microsoft in the Data Agent MCP Server Guide. If the query is performed using the user’s identity, the agent enforces the semantic model’s row-level and column-level security; if the application’s identity is used, access control must be enforced within the Rayfin Function itself. As we explained in our article on MCP in the enterprise, it is also advisable to define where the responses are processed and stored.
Security, Identity, and Traceability
An application connected to corporate data must address security at three levels. Connectors use delegated user authentication, so that each query adheres to the user’s permissions on the Fabric resource. External connections made by Rayfin Functions, on the other hand, use the application’s identity, so each function must verify that the invoker is authorized for the requested operation. Finally, the permissions of Rayfin entities protect the application’s own state.
The row-level security of a semantic model does not protect direct SQL access to the underlying Lakehouse or Warehouse. If the application combines both approaches, each requires its own controls.
Traceability completes the design. Recording who requested each operation, with what parameters, which job executed it, and what result it produced allows for auditing decisions and quickly diagnosing incidents. This approach is supported by data governance with Microsoft Fabric, which establishes which assets can be exposed and under what responsibilities.
When does this approach make sense?
Fabric Apps and Rayfin provide the most value when the process goes beyond simply querying data. Demand planning, scenario management, approving forecasts, or reviewing models are scenarios in which the user needs to analyze, make decisions, and document them without leaving the platform. If the need is limited to exploring information, a Power BI report remains the most straightforward option.
Before beginning development, it’s important to evaluate four aspects.
- Business process. What decisions the application must support and what information the user needs at each step.
- Data freshness. How often the data sources are updated and what latency each decision can tolerate.
- Capacity and cost. What resource consumption is generated by concurrency, query complexity, and job duration.
- Platform maturity. Which preview features will be used, their regional availability, and the project’s licensing and support requirements.
How Intelequia Can Help You
At Intelequia, we combine data engineering, software development, and artificial intelligence to transform data platforms into tools that improve the operations of every organization.
We approach these projects from the perspective of the business process, not the technology. We identify the use case with the highest return on investment, design the integration architecture and permissions model, and validate the solution with your users using metrics such as resolution time, reduction in manual tasks, and decision traceability.
If your organization already works with Microsoft Fabric, we can help you identify the first use case and bring it into production with confidence. Contact our team.