AI enablement: Claude, Power BI, and Microsoft 365


Husco International builds hydraulic and electro-mechanical components for the automotive and off-highway markets, and has done it for more than eighty years. The company is privately owned and runs on Microsoft. Power BI reports and dashboards run the business day to day.
A working system, and no way to trust it
As a Microsoft shop they started with Copilot, which covered breadth and fell short on the depth their business people needed, so they moved to Claude and shifted from individual licenses to a Team license to protect their IP. One of their engineers had already built MCP servers connecting Claude to Power BI and the Microsoft 365 estate, and those servers returned answers.
What the audit covered
The business brought in Red Foundry to say whether MCP was the right architecture, whether the answers were correct, and whether access stayed inside each user's own permissions. We reviewed the server code, the tool definitions, and the skill against engineering best practices. Three capability gaps came back: the servers could not list the semantic models a question needed, they had no way to return a visualization, and nothing throttled a query before it reached the estate.
Ask in plain language, get the answer the report would give
A Power BI MCP server that reaches further than the native one
Microsoft's official connector could not expose the semantic models Husco's questions depend on, so we built our own server. It discovers semantic models against an allowlist, returns a formalized response with a summary, the KPI, a chart spec, and the underlying table, and throttles queries with row limits and concurrency caps. We also extended it to read report definitions, so an answer matches the report a user is looking at instead of being arithmetically correct against a different slice.
One identity, all the way through
The server carries the signed-in user's own identity to Power BI and Microsoft 365, using delegated on-behalf-of authentication against Entra ID with JWT validation and no stored secrets. Claude sees what that person could already open natively. On top of it we built a skill that classifies each question, holds a fixed answer shape, and carries Husco's own definitions in a companion glossary, so the terms in an answer mean what they mean in the business.
Governance and rollout
Testing what a good answer is, and who may see it
No definition of a good answer existed, so we wrote one with the business: a set of the questions people actually ask, each with the answer it should produce, run against the live setup. Permissions got their own test. Two users with different entitlements ask the same question, and each may see only their own data. A leak across that boundary blocks the capability from going live, and blocks a write harder than a read.
What Husco can scale from
Every user now runs one published version of the skill through Claude organization settings, so a fix reaches everyone at once. Per call telemetry captures the user, tool, model, duration, rows, and outcome, alongside token cost, which gives Husco a spend forecast before they widen agent use. They keep a runbook, admin controls for the Microsoft 365 read and write case, and a change log that records the evidence behind each rule in the skill and the condition under which that rule retires.
Ready to get started?
We see our clients as our partners and are invested in their success. We ensure what we build for our clients will have a positive ROI. We never build anything just for the sake of it.





