BI tools (Looker, Power BI)
On this page
Connect Looker, Power BI or another BI tool directly to your gold data, the clean analysis-ready tables Lucen builds from your sources. Where the access lives depends on who owns your BigQuery warehouse.
Overview
Every Lucen organization has a gold layer: one dataset with one table per business question your models answer. BI tools connect to it read-only. There are two cases:
- Blumie-managed warehouse. Your gold data lives in a project Blumie runs. You do not need a Google Cloud project or any Google identity: Blumie provisions a dedicated read-only service account for your organization and you download its key once from the Lucen portal.
- Your own BigQuery project. The datasets live in your GCP project, which you own and pay Google for directly. You grant access to your BI tool yourself, in your own project, and Blumie never touches your IAM.
Not sure which one you have? Ask your organization owner, or open the Lucen portal: if the BI access page shows connection details, your warehouse is Blumie-managed.
Blumie-managed warehouse: the portal flow
- Open Lucen > BI access in the portal sidebar.
- If the page shows "No BI connection yet", use Request access: it opens a ticket to Blumie and we enable it for your organization. This is a one-time setup we perform, never self-service, so your data stays governed.
- Once enabled, the page shows your connection details: the billing project, the data project, the dataset name and the service account email. Every field has a copy button.
- As an organization owner, use Download key. Read the warning: the key is a credential and it is shown only once. Copy it or download it as a
.jsonfile, then store it where your team keeps credentials. - Follow the per-tool steps on the same page: Looker, Power BI or generic JDBC/ODBC.
If the key was already revealed, the button becomes Generate new key. The current key stops working the moment a new one is generated, so reconnect your dashboards right after rotating. Ask an organization owner if you do not see the key actions; members can view the connection details but cannot download or rotate the key.
Good to know
- The key can read exactly one dataset: your gold data. It cannot see raw sources, other layers or other organizations.
- Queries run against the billing project shown on the page. Today it is the same as the data project. If it ever changes, we will let you know and you only update this field in your BI tool.
- The dataset picker in some BI tools may look empty. Type the dataset name exactly as shown on the page.
- Looker persistent derived tables (PDTs) are not supported: the service account is read-only and there is no writable scratch dataset.
Your own BigQuery project: grant access yourself
Your gold tables live in a dataset named {your_slug}_gold in your own project. Grant a person or a service account read access to that dataset only, plus permission to run queries:
# 1. Read access on the gold dataset only (dataset-level IAM)
bq add-iam-policy-binding \
--member="user:analyst@yourcompany.com" \
--role="roles/bigquery.dataViewer" \
YOUR_PROJECT_ID:your_slug_gold
# 2. Permission to run query jobs in your project
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
--member="user:analyst@yourcompany.com" \
--role="roles/bigquery.jobUser"Use a service account and its JSON key if your BI tool connects with a key (the common path for Power BI), or a user account if your tool signs in with Google OAuth. Avoid roles/bigquery.user and roles/bigquery.dataViewer at project level: they expose dataset names and metadata beyond your gold data.
Keeping the credential safe
- Treat the key like a password. Anyone holding it can read your gold data.
- Do not commit it to a repository or paste it into chat.
- If a key leaks or a team member leaves, generate a new key from the portal; the old one stops working immediately.
- Blumie sweeps unused keys daily and alerts if anything unexpected is found.
