PathixDataverse Forensics
Forensics for Dynamics 365 and Dataverse

Map the write paths.
Audit every role.

One deterministic graph of your Dynamics 365 and Dataverse environment: what writes every column, who can actually reach it, what your site serves to visitors who never signed in, and what changed since the last scan.

Book a demoRead the sample report →
account.creditlimit48Credit Limit88th percentile5 writers · 3 readersPLGPluginAccount_PreUpdate_CreditCheck✦ AI-DERIVED41FLWCloud flowSync credit limit from TreasuryDETERMINISTIC35WFClassic workflowRe-tier on credit changeDETERMINISTIC22BRBusiness ruleCap credit limit at tierDETERMINISTIC14JSForm scriptfrm_account_credit.jsDETERMINISTIC6DSHDashboardSales Ops · Credit at riskDETERMINISTIC26PBIPower BI reportTreasury exposure (weekly)DETERMINISTIC19DFIDataflow integrationSAP S/4 → AR syncDETERMINISTIC31WRITERSTARGET COLUMNREADERSsalience · graph prominence, not riskAI-derived · never overrides a deterministic edge
72 deterministic checksRead-only application userSelf-hosted in your AzureMetadata-only, never record valuesEvery edge shows how Pathix knows it
The platform

One platform, six surfaces.

A Dynamics environment accretes automation and access for years. Pathix reads what is deployed, holds it in one graph, and gives each of these questions an answer with the evidence attached.

DEPENDENCY ANALYSIS

What writes to this column?

Resolved across plugins, cloud flows, classic workflows, business rules, form scripts and dataflows, down to the column. Plugins are read from their compiled IL, flows from their definition JSON, and every edge states how Pathix knows it.

Plugins · ILFlows · JSONWorkflows · XAMLForm scripts

Dependency analysis

EFFECTIVE PERMISSIONS

Who can actually reach it?

Effective permissions resolved from either end: every principal that can reach a column and the path each one takes, through roles, teams, business units, the manager hierarchy and column security. The role shared between humans and integrations stops hiding in the assignment list.

RolesTeamsBusiness unitsColumn security

Effective permissions

POWER PAGES EXPOSURE

What can an anonymous visitor reach?

Site reach is decided by six layers of configuration, and Pathix reads five of them: web roles, table permissions, column permissions, page rules and site settings. Findings state what the configuration grants, never that data is being served.

Web rolesTable permissionsPage rulesSite settings

Power Pages exposure

CHANGE TRACKING

What changed since the last scan?

Every scan is diffed against the one before: new and removed writers, source changes, and security deltas down to a single privilege grant or a role that moved from Local to Global. It also catches the changes nobody made on purpose, before they become incidents.

New writersNew grantsScope changesDelta ledger

Change tracking

AI ESTATE

What is your AI set up to reach?

Copilot Studio agents, agent flows, AI Builder models, prompt columns and knowledge configurations, read as components of the same graph: each tool's target and whose connection it runs on, the columns an assistant is set up to answer from, and who can start an agent with nobody present. Configuration, never conversations.

Agents · toolsPrompt columnsKnowledge sourcesAutonomous triggers

AI estate

SECURITY FINDINGS

What is misconfigured, and what does it map to?

Every scan runs the full catalog: over-privileged and shared identities, column-security gaps, offboarding residue, open endpoints and anonymous reach. Each condition names the control it is evidence for where one exists, and stays uncited where dressing a hygiene gap up as a control finding would cheapen the real ones.

Access & least privilegeIdentity lifecycleExternal connectionsControl mappings

What we check

How it works: a read-only application user scans your environments from inside your own Azure, deployed from a Bicep template with a guided wizard. First scan under an hour.

The full walkthrough →
Four jobs, one graph

What do you want to do with it?

Every door draws from the same graph. The difference is the job, and the words for it.

D365 ADMIN · SECURITY ANALYST

Answer the questions you get every day, in seconds.

  • What changed since the last scan, even what you didn't change
  • Who can really write this column
  • Touchpoints: every writer and reader of a column, ranked by salience

With AI on: hand an incident to an agent over the MCP and it traces what the change actually touches.

Explore Everyday

SINCE YOUR LAST SCAN · #8 → #9
+1 new finding⤴ 1 regressed↑ 1 rising hotspot9 since last seen
HSharedRole · ‘Legacy CRM Admin’ (security-metadata write) shared by a human and an application user
⤴ regressed · resolved earlier, currently open again
HStepImpersonatesDisabledUser · plugin step ‘ContosoLegacy.Sync.AccountBalanceShadow’ runs as disabled user ‘Marcus Yoder’
+1 new · the impersonation fails every time it fires
The console

One place for every environment.

Every scan rolls up here: what changed since you last looked, the findings and hotspots that need attention, and an honest read on what the scan could not resolve. Findings rank by severity, hotspots by salience, and the two never merge into one number.

The Pathix home console. Five tiles: three environments, 22 open findings, 6 high, 4 hotspots, and plus three since the last scan. A riskiest-finding spotlight (a high-severity privileged role shared between humans and integrations) sits beside a top-hotspot spotlight (the creditlimit field at salience 48), never merged. Below: open findings ranked by severity, hotspots ranked by salience (creditlimit 48, an AI-derived shadow writer 35, an orphaned reader 26, creditonhold 24), and a coverage panel showing 40 percent Declared, 50 percent Parsed, 10 percent AI-derived confidence with four unvalidated AI-derived edges to review. A banner reads: two axes, never merged into one list.
How answers are made

Deterministic first. AI on a leash.

The graph is built by parsing what is deployed: compiled plugin IL, workflow XAML, flow JSON, Power Pages configuration, security roles. That deterministic core is the product. AI is optional, off by default, bring-your-own-key, and works under three rules.

RULE 01

AI narrates. It never overrides.

Deterministic results are the record. AI can explain a plugin or propose an edge the parser could not resolve; it cannot alter, outrank, or delete a deterministic result.

RULE 02

Every AI claim carries its evidence.

An AI-derived edge is labeled, ships with the quoted source that justifies it, and waits for your validation. You judge; it argues.

RULE 03

Unknowns stay visible.

A write whose target cannot be resolved is reported as Unresolved, a first-class result. No answer is padded to look more complete than the evidence allows.

How Pathix uses AI →The graph speaks MCP: 22read-only tools for your agent →
The console

The real console, on sample data.

Not a mockup and not a video: the actual Pathix console, loaded with a sample environment. A walkthrough runs on that same environment, so you can open a finding, follow a column to its touchpoints and sort the hotspots by salience before anyone touches your tenant.

COVERAGE & BLIND SPOTS · SAMPLE ENVIRONMENT
Deterministic92%
AI-derived8%

A low signal count is not “all clear.” Not everything is scannable, and Pathix tells you what it could not see.

Consultancies: land a paid assessment in hours, bid the migration fixed-price with the discovery risk measured instead of guessed, then stay on for delivery.

Pathix for consultancies →
Built to survive a security review

Self-hosted, read-only, metadata-only.

The boundaries are architectural, not promises. Deploy it in your own tenant, read the schema yourself, and check the exact read-only role before you grant it.

In your own Azure

Deploys into the customer's own subscription from a Bicep template and a guided wizard. Nothing about running it requires data to leave the tenant.

Read-only, metadata-only

A read-only application user. Pathix reads schema, registrations, and definitions, and never stores, transmits, or analyzes your business record values.

The AI tier holds the same line

Turn AI on with your own key and the metadata-only boundary still applies. Record values stay out of the AI path too.

See exactly what Pathix reads, and what it never touches →Read the security white paper (PDF) →

See what Pathix finds in a real environment.

A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install. Bring the questions your current tools can't answer.

Book a demoRead the sample report →
© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π