PathixDataverse Forensics
Capability · AI estate

What does your AI's configuration put in reach?

Copilot Studio agents, agent flows, AI Builder models, prompt columns and their knowledge sources are components like any other, and Pathix reads them into the same graph as your plugins and flows: what each one is set up to touch, whose access it runs with, and who can reach it. AI Audit reviews Pathix's own AI-derived edges. AI estate inventories yours. Pathix's own optional AI layer is a different page and a different thing.

Book a walkthrough →Or jump to the 6AI estate conditions →
The estate, inventoried

Every agent, model, prompt column and knowledge source, counted once.

Including the agents nobody published and the models Microsoft shipped, split by who authored them, with the settings that matter marked on the row: no authentication, a tool on its maker's connection, a draft that differs from what runs. Figures on this page are from Pathix's own sample environment, scanned 2026-09-10.

Agents
5
AI Builder models
35
AI prompt columns
2
Sensitive columns exposed
0
Open AI findings
2
AGTCopilot Studio agents1 Microsoft4 authorship unread1 no auth1 maker tool5
AIMAI Builder models32 Microsoft3 authorship unread35
APCAI prompt columns2 authorship unread2
AFLWAgent flows5 Microsoft1 authorship unread6
KNWKnowledge sources8 Microsoft9 authorship unread17
The footprint

Every tool, resolved to what it is set up to touch.

An agent is a bundle of tools, and Pathix reads each one the way it reads a plugin or a flow: the table it writes, the flow it calls, the agent it hands off to, and whose connection it runs on. A tool whose target the agent picks at run time stays on the page as a capability rather than a write, because nobody decided in advance what it would touch.

sim_LoanDeskAgentPUBLISHEDAUTONOMOUSUNMANAGED1 WRITE · 0 READS · 5 INVOCATIONS · 1 UNRESOLVED · GRAPH PROMINENCE 34TH PERCENTILE · SAMPLE ENVIRONMENTTOOLS · 4TOOLKINDTARGETRUNS ASCONFIDENCEAdd a new row to selected environmentDataverse actionsim_bankengagementEND USERDETERMINISTICUNRESOLVEDPerform a bound action in selected environmentDataverse actionaccountEND USERUpdate a row in selected environmentDataverse actionChosen by the agent at run timeEND USERsim Loan Desk Review FlowAgent flowsim Loan Desk Review FlowEND USERDETERMINISTICDeterministic where the definition pins a target, unresolved for the rest. A table the agent chooses at run time is recorded as a capability, not an edge.KNOWLEDGE · 1SOURCESCOPECOLUMNS INDEXEDComplianceReview_BranchDaySummary…sim_bankengagement, sim_branchdaysummary, sim_compliancereview0 · 3 grounded tables list no columns of their own

What resolves lands in the same footprint, with the same salience, as every other component in the graph. The page is a floor, not a ceiling: an agent's topics are not read for what they touch.

The AI writer on a table

One column an AI writes, and two beside it nobody authored.

A prompt column looks like a computed column and is not: a model writes it, and the platform creates two companion columns beside it that the same run writes. Pathix attributes all three as writes, reads the inputs the prompt is bound to, and never reads the prompt text itself.

Engagement SummaryCODE INTERPRETER ONRETRIEVAL LIMIT 30 ROWSMODEL GPT-41-MINIsim_bankengagement · sim_engagementsummary · GRAPH PROMINENCE 97TH PERCENTILE · MODEL BEHIND IT: BANK ENGAGEMENT - ENGAGEMENT SUMMARYWRITES · 3 COLUMNSsim_bankengagement.sim_engagementsummarythe prompt column itselfsim_bankengagement.sim_engagementsummary_promptcolumndetailsplatform companion · run detailssim_bankengagement.sim_engagementsummary_promptcolumnstatusplatform companion · run statusINPUTS · 7 READSsim_bankengagement.modifiedonINPUT COLUMNsim_bankengagement.sim_bankengagementidGROUNDING FILTERsim_bankengagement.sim_estimatedvalueINPUT COLUMNsim_bankengagement.sim_nameINPUT COLUMNsim_bankengagement.sim_riskflagINPUT COLUMNsim_bankengagement.sim_sladuedateINPUT COLUMNsim_bankengagement.statecodeINPUT COLUMNCode interpreter is on: the platform generated code for this prompt that Pathix does not read, so the declared inputs and writes are a floor, not a ceiling.The prompt's instruction text is not read or stored; inputs and outputs come from the platform's own typed bindings.
DETERMINISTIC · EVERY EDGE HERE IS READ FROM CONFIGURATION, NONE IS AI-DERIVED
Knowledge

Which of your sensitive columns an AI is set up to answer from.

A column indexed as knowledge is answerable in plain English by anyone who can reach the agent or app copilot behind it. Pathix reads the knowledge configuration behind every assistant, crosses it with the columns you have secured or marked sensitive, and with whether the assistant asks anyone to sign in. It reports what is in scope, never what an AI has said.

Everything an AI can answer from, sensitive first.WHAT IS EXPOSEDANSWERABLE THROUGHAGENT SIGN-INaccountcolumns not enumerated by the platform· 12 sensitive columns on this table; column-level exposure not enumeratedApp copilot (Test App)(no bound consumer read)accountcolumns not enumerated by the platform· 12 sensitive columns on this table; column-level exposure not enumeratedApp copilot (Credit Limit Test App)(no bound consumer read)accountcolumns not enumerated by the platform· 12 sensitive columns on this table; column-level exposure not enumeratedApp copilot in mspp_PowerPageManagementcontactcolumns not enumerated by the platform· 13 sensitive columns on this table; column-level exposure not enumeratedApp copilot (Managed Contact App)(no bound consumer read)Four of 111 rows in the sample.86 grounded tables list no columns of their own, so what each one exposes is grounding, not a column Pathix can name.Pathix read what was declared indexable, not what an AI answered with.

A secured or sensitive column indexed for an AI is a finding, and one indexed for an agent with no authentication is a high one. It is the same question this site asks about Power Pages, pointed at a newer surface: what does the configuration serve, and to whom.

Whose connection, and who can start it

Each tool runs on someone's connection. The page says whose.

A tool runs either as the person talking to the agent or on a connection its maker provided, and the second kind acts with the author's access for every caller. Pathix marks it on the inventory and raises it as a finding, counts the agent identities that hold security roles, and resolves their reach through the same effective-permissions engine as any other principal.

AGENT IDENTITIES WITH ROLES
0

No Dataverse identity managed on behalf of an agent holds a security role in this scan.

UNRESOLVED AI BINDINGS

Every AI binding in this scan resolved to something Pathix can name.

A binding whose target could not be named: deleted, outside this scan, or not readable at the scanner's scope.

WRITES TO ANOTHER ENVIRONMENT
AGTKiosk Agentanother environment

At least this many. A step whose target environment could not be read is recorded on the component and not counted here.

AUTONOMOUS TRIGGERS

An external trigger is configured to let a flow start the agent with no person present.

TRIGGERAGENTFLOWS WIRED TO START THE AGENT
Recurring Copilot Triggersim_LoanDeskAgentRecurring Copilot Trigger, When a row is added, modified or deleted
When a row is added, modified or deletedsim_LoanDeskAgentRecurring Copilot Trigger, When a row is added, modified or deleted
The ledger, extended

The estate changes, and the ledger already keeps it.

Agents, models and knowledge sources land in the same scan-over-scan ledger as everything else, so a knowledge source that appeared on Friday is still there on Monday. What changed inside an agent, a tool added or a source widened, is not diffed at this tier, and the page says so rather than pretending.

Sep 10KNWApp copilot (cat_DataverseCompanionApp)Knowledge source
Sep 9KNWApp copilot (Credit Limit Test App)Knowledge source
Sep 9KNWApp copilot (cat_DataverseCompanionApp, Microsoft 365 surface)Knowledge source
The lines Pathix holds

Pathix reads structure, never conversations.

Transcripts, prompt text and run history are customer content and are never read: Pathix reads what your AI is built to do, and nothing it said. Where the estate runs past what a scan can read, the page says so instead of rounding the gap away:

  • Knowledge outside Dataverse, such as a SharePoint site, a public website or uploaded files, is listed by name and not scanned.
  • A tool whose table the agent chooses at run time is recorded as a capability, not a write, and an agent's topics are not read, so an agent's page is a floor rather than a complete reach.
  • Nothing here says a value was served to anyone: a column indexed as knowledge was put in scope, and the identity an assistant queries under is not read.
What it raises

6 AI estate conditions, checked on every scan.

An open agent, a tool on its maker's credentials, a sensitive column indexed as knowledge, an agent or model owned by someone who has left, an agent the platform reports as unlicensed. They run alongside the rest of the catalog and are triaged the same way; none carries a framework citation, because they are configuration facts about an agent, not evidence for a control.

Beside the platform's own tooling

Microsoft governs agents. It stops one layer up.

The Power Platform admin center inventories agents well, DLP enforces connector classes at publish time, Entra gives agents identities, and Purview watches interactions. All of it is real, and all of it stops at the connector: which Dataverse table a tool touches, whose access it runs with, and what changed since last month are the questions below that line, and they are the same questions Pathix answers everywhere else in the graph.

What Microsoft's agent governance covers, and what it doesn't →

Where this fits

The same graph, asked a newer question.

Find out what your AI is set up to reach.

A walkthrough runs on Pathix's sample environment, so you can see an agent's tools resolved, a prompt column's three writes and a knowledge source crossed with sensitivity before anyone touches your tenant.

Book a walkthrough →Read the sample report
© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π