PathixDataverse Forensics
Forensics for Dynamics 365 and Dataverse

Map the write paths.
Audit every role.

One deterministic graph of your Dynamics 365 and Dataverse environment: what writes every field, what each plugin is built to do, who can touch what.

Book a demoSee it on sample data →
account.creditlimit48Credit Limit88th percentile5 writers · 3 readersPLGPluginAccount_PreUpdate_CreditCheck✦ AI-DERIVED41FLWCloud flowSync credit limit from TreasuryPARSED35WFClassic workflowRe-tier on credit changePARSED22BRBusiness ruleCap credit limit at tierDECLARED14JSForm scriptfrm_account_credit.jsPARSED6DSHDashboardSales Ops · Credit at riskDECLARED26PBIPower BI reportTreasury exposure (weekly)PARSED19DFIDataflow integrationSAP S/4 → AR syncPARSED31WRITERSTARGET FIELDREADERSsalience · graph prominence, not riskAI-derived · never overrides a deterministic edge
40 deterministic checksRead-only application userSelf-hosted in your AzureMetadata-only, never record valuesEvery edge shows how Pathix knows it
How it works

Scan. Resolve. Act.

01

Scan

A read-only application user reads schema, registrations, and definitions. Never your record values.

Bicep templateGuided wizardFirst scan under an hour
$ az deployment sub create ...
read-only application user granted
scan complete · 3 environments
02

Resolve

Every component parsed into one graph, including what the platform itself cannot interpret: compiled plugin IL, classic-workflow XAML, flow JSON.

Plugins · ILFlows · JSONWorkflows · XAMLForm scriptsRoles
account.creditlimit ← 6 writers
confidence: Declared · Parsed · AI-derived
03

Act

Findings ranked by severity, touchpoints ranked by salience, migrations sequenced. All of it callable by your agents over the MCP.

FindingsTouchpointsMigration plansMCP
> find_writers("account", "creditlimit")
6 components · evidence attached

The full walkthrough, step by step →

Four jobs, one graph

What do you want to do with it?

Every door draws from the same graph. The difference is the job, and the words for it.

D365 ADMIN · SECURITY ANALYST

Answer the questions you get every day, in seconds.

  • What changed since the last scan, even what you didn't change
  • Who can really write this field
  • Touchpoints: every writer and reader of a column, ranked by salience

With AI on: hand an incident to an agent over the MCP and it traces what the change actually touches.

Explore Everyday

SINCE YOUR LAST SCAN · #8 → #9
+1 new finding⤴ 1 regressed↑ 1 rising hotspot9 since last seen
HSharedRole · ‘Legacy CRM Admin’ (security-metadata write) shared by a human and an application user
⤴ regressed · resolved earlier, currently open again
HStepImpersonatesDisabledUser · plugin step ‘ContosoLegacy.Sync.AccountBalanceShadow’ runs as disabled user ‘Marcus Yoder’
+1 new · the impersonation fails every time it fires

AI is optional and off by default. How Pathix uses AI →

The console

One place for every environment.

Every scan rolls up here: what changed since you last looked, the findings and hotspots that need attention, and an honest read on what the scan could not resolve.

The Pathix home console. Five tiles: three environments, 22 open findings, 6 high, 4 hotspots, and plus three since the last scan. A riskiest-finding spotlight (a high-severity privileged role shared between humans and integrations) sits beside a top-hotspot spotlight (the creditlimit field at salience 48), never merged. Below: open findings ranked by severity, hotspots ranked by salience (creditlimit 48, an AI-derived shadow writer 35, an orphaned reader 26, creditonhold 24), and a coverage panel showing 40 percent Declared, 50 percent Parsed, 10 percent AI-derived confidence with four unvalidated AI-derived edges to review. A banner reads: two axes, never merged into one list.
Three axes, never merged

Severity, salience, and confidence stay apart.

Most tools collapse everything into one number. Blend these three and all three read wrong.

SEVERITY

The security verdict

A deterministic check that fired, ranked Critical to Info. Findings only. Salience never enters this ordering.

SALIENCE

Graph prominence, 0 to 100

How noisy a field or component is in the graph: how many things write it, whether it is sensitive, whether it sits next to a finding. It ranks what is prominent, not what is risky. A low score is not a safety verdict.

CONFIDENCE

How Pathix knows each edge

Declared, pinned by platform structure. Parsed, resolved from the component's own logic. AI-derived, evidence-coupled and never overriding a deterministic edge. Unresolved, a write we found but could not trace to a column, shown rather than quietly dropped.

See salience live in the demo →Read the guide →
The live demo

The real console, on sample data.

Not a mockup and not a video: the actual Pathix console, loaded with a sample environment. Click into a finding, open the touchpoints for a field, sort the hotspots by salience. Nothing to install, and no access to your tenant.

COVERAGE & BLIND SPOTS · SAMPLE ENVIRONMENT
Declared38%
Parsed54%
AI-derived8%

A low signal count is not “all clear.” Not everything is scannable, and Pathix tells you what it could not see.

Consultancies: land a paid assessment in hours, bid the migration fixed-price with the discovery risk measured instead of guessed, then stay on for delivery.

Pathix for consultancies →
Built to survive a security review

Self-hosted, read-only, metadata-only.

The boundaries are architectural, not promises. Deploy it in your own tenant, read the schema yourself, and check the exact read-only role before you grant it.

In your own Azure

Deploys into the customer's own subscription from a Bicep template and a guided wizard. Nothing about running it requires data to leave the tenant.

Read-only, metadata-only

A read-only application user. Pathix reads schema, registrations, and definitions, and never stores, transmits, or analyzes your business record values.

The AI tier holds the same line

Turn AI on with your own key and the metadata-only boundary still applies. Record values stay out of the AI path too.

See exactly what Pathix reads, and what it never touches →Read the security white paper (PDF) →

See what Pathix finds in a real environment.

A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install. Bring the questions your current tools can't answer.

Book a demoExplore the live demo →
© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π