One deterministic graph of your Dynamics 365 and Dataverse environment: what writes every column, who can actually reach it, what your site serves to visitors who never signed in, and what changed since the last scan.
A Dynamics environment accretes automation and access for years. Pathix reads what is deployed, holds it in one graph, and gives each of these questions an answer with the evidence attached.
Resolved across plugins, cloud flows, classic workflows, business rules, form scripts and dataflows, down to the column. Plugins are read from their compiled IL, flows from their definition JSON, and every edge states how Pathix knows it.
Dependency analysis →
Effective permissions resolved from either end: every principal that can reach a column and the path each one takes, through roles, teams, business units, the manager hierarchy and column security. The role shared between humans and integrations stops hiding in the assignment list.
Effective permissions →
Site reach is decided by six layers of configuration, and Pathix reads five of them: web roles, table permissions, column permissions, page rules and site settings. Findings state what the configuration grants, never that data is being served.
Power Pages exposure →
Every scan is diffed against the one before: new and removed writers, source changes, and security deltas down to a single privilege grant or a role that moved from Local to Global. It also catches the changes nobody made on purpose, before they become incidents.
Change tracking →
Copilot Studio agents, agent flows, AI Builder models, prompt columns and knowledge configurations, read as components of the same graph: each tool's target and whose connection it runs on, the columns an assistant is set up to answer from, and who can start an agent with nobody present. Configuration, never conversations.
AI estate →
Every scan runs the full catalog: over-privileged and shared identities, column-security gaps, offboarding residue, open endpoints and anonymous reach. Each condition names the control it is evidence for where one exists, and stays uncited where dressing a hygiene gap up as a control finding would cheapen the real ones.
What we check →
How it works: a read-only application user scans your environments from inside your own Azure, deployed from a Bicep template with a guided wizard. First scan under an hour.
The full walkthrough →Every door draws from the same graph. The difference is the job, and the words for it.
With AI on: hand an incident to an agent over the MCP and it traces what the change actually touches.
Every scan rolls up here: what changed since you last looked, the findings and hotspots that need attention, and an honest read on what the scan could not resolve. Findings rank by severity, hotspots by salience, and the two never merge into one number.
The graph is built by parsing what is deployed: compiled plugin IL, workflow XAML, flow JSON, Power Pages configuration, security roles. That deterministic core is the product. AI is optional, off by default, bring-your-own-key, and works under three rules.
Deterministic results are the record. AI can explain a plugin or propose an edge the parser could not resolve; it cannot alter, outrank, or delete a deterministic result.
An AI-derived edge is labeled, ships with the quoted source that justifies it, and waits for your validation. You judge; it argues.
A write whose target cannot be resolved is reported as Unresolved, a first-class result. No answer is padded to look more complete than the evidence allows.
Not a mockup and not a video: the actual Pathix console, loaded with a sample environment. A walkthrough runs on that same environment, so you can open a finding, follow a column to its touchpoints and sort the hotspots by salience before anyone touches your tenant.
A low signal count is not “all clear.” Not everything is scannable, and Pathix tells you what it could not see.
Consultancies: land a paid assessment in hours, bid the migration fixed-price with the discovery risk measured instead of guessed, then stay on for delivery.
Pathix for consultancies →The boundaries are architectural, not promises. Deploy it in your own tenant, read the schema yourself, and check the exact read-only role before you grant it.
Deploys into the customer's own subscription from a Bicep template and a guided wizard. Nothing about running it requires data to leave the tenant.
A read-only application user. Pathix reads schema, registrations, and definitions, and never stores, transmits, or analyzes your business record values.
Turn AI on with your own key and the metadata-only boundary still applies. Record values stay out of the AI path too.
A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install. Bring the questions your current tools can't answer.