Copilot Studio agents, agent flows, AI Builder models, prompt columns and their knowledge sources are components like any other, and Pathix reads them into the same graph as your plugins and flows: what each one is set up to touch, whose access it runs with, and who can reach it. AI Audit reviews Pathix's own AI-derived edges. AI estate inventories yours. Pathix's own optional AI layer is a different page and a different thing.
Including the agents nobody published and the models Microsoft shipped, split by who authored them, with the settings that matter marked on the row: no authentication, a tool on its maker's connection, a draft that differs from what runs. Figures on this page are from Pathix's own sample environment, scanned 2026-09-10.
An agent is a bundle of tools, and Pathix reads each one the way it reads a plugin or a flow: the table it writes, the flow it calls, the agent it hands off to, and whose connection it runs on. A tool whose target the agent picks at run time stays on the page as a capability rather than a write, because nobody decided in advance what it would touch.
What resolves lands in the same footprint, with the same salience, as every other component in the graph. The page is a floor, not a ceiling: an agent's topics are not read for what they touch.
A prompt column looks like a computed column and is not: a model writes it, and the platform creates two companion columns beside it that the same run writes. Pathix attributes all three as writes, reads the inputs the prompt is bound to, and never reads the prompt text itself.
A column indexed as knowledge is answerable in plain English by anyone who can reach the agent or app copilot behind it. Pathix reads the knowledge configuration behind every assistant, crosses it with the columns you have secured or marked sensitive, and with whether the assistant asks anyone to sign in. It reports what is in scope, never what an AI has said.
A secured or sensitive column indexed for an AI is a finding, and one indexed for an agent with no authentication is a high one. It is the same question this site asks about Power Pages, pointed at a newer surface: what does the configuration serve, and to whom.
A tool runs either as the person talking to the agent or on a connection its maker provided, and the second kind acts with the author's access for every caller. Pathix marks it on the inventory and raises it as a finding, counts the agent identities that hold security roles, and resolves their reach through the same effective-permissions engine as any other principal.
No Dataverse identity managed on behalf of an agent holds a security role in this scan.
Every AI binding in this scan resolved to something Pathix can name.
A binding whose target could not be named: deleted, outside this scan, or not readable at the scanner's scope.
At least this many. A step whose target environment could not be read is recorded on the component and not counted here.
An external trigger is configured to let a flow start the agent with no person present.
Agents, models and knowledge sources land in the same scan-over-scan ledger as everything else, so a knowledge source that appeared on Friday is still there on Monday. What changed inside an agent, a tool added or a source widened, is not diffed at this tier, and the page says so rather than pretending.
Transcripts, prompt text and run history are customer content and are never read: Pathix reads what your AI is built to do, and nothing it said. Where the estate runs past what a scan can read, the page says so instead of rounding the gap away:
An open agent, a tool on its maker's credentials, a sensitive column indexed as knowledge, an agent or model owned by someone who has left, an agent the platform reports as unlicensed. They run alongside the rest of the catalog and are triaged the same way; none carries a framework citation, because they are configuration facts about an agent, not evidence for a control.
The Power Platform admin center inventories agents well, DLP enforces connector classes at publish time, Entra gives agents identities, and Purview watches interactions. All of it is real, and all of it stops at the connector: which Dataverse table a tool touches, whose access it runs with, and what changed since last month are the questions below that line, and they are the same questions Pathix answers everywhere else in the graph.
What Microsoft's agent governance covers, and what it doesn't →
What writes to this column, now including prompt columns and the pinned tools of every agent. One answer across code, flows and AI.
Read it →The engine an agent identity's roles resolve through, once it holds any: the same answer for a person, an integration and an agent.
Read it →The ledger the estate's changes land in, with the scan that caught each one and a rolling seven-day window.
Read it →A walkthrough runs on Pathix's sample environment, so you can see an agent's tools resolved, a prompt column's three writes and a knowledge source crossed with sensitivity before anyone touches your tenant.