PathixDataverse Forensics
Capability · Change tracking

What changed since the last scan?

Every Pathix scan is compared with the one before it, and the differences land in an append-only ledger: new and removed writers, security deltas down to a single privilege grant, a Power Pages site setting that moved, a finding that opened, resolved, or came back. The answer you documented in March is not the answer in June, and this is the page of the product that knows the difference.

228
CHANGES IN ONE 30-DAY WINDOW
28
SCANS COMPARED
2
WAYS TO READ THEM

Figures on this page are the Dev-Clean sample environment, the same simulated org behind the worked dependency chain.

The timeline view

Each scan tells you what it found different.

One card per scan, and the card leads with the three numbers that matter: what opened, what resolved, and everything else. A scan that resolved eight findings reads as exactly that, before you expand a single row. When one change stands out, the card says which, and says precisely what the number on it means.

Scan #618/23/20260 new8 resolved1 otherPOWER PAGES · 1Site settings changed · Scheduling Site 1FINDINGS · 8 RESOLVEDC×6 SecurityMetaWriteGrantedToApplicationUserMPortalOpenRegistrationEnabledMPortalLocalLoginEnabledScan #558/22/20260 new0 resolved24 otherMOST GRAPH-PROMINENT CHANGE IN THIS SCAN 11 Privilege granted · Service Writer · usersettingsSECURITY · 24×22 Privilege granted · usersettings×2 Privilege scope changed · usersettings
The browse view

The whole window, grouped until you pick.

The same ledger as an aggregate: a window of 7, 30 or 90 days, every change kind counted under its category, and the rows loading when you select a kind. The tree is how a month of changes stays readable, and the counts are how a category you were not thinking about gets your attention: five site setting changes sitting next to a hundred dependency changes is a ratio worth reading in both directions. Filter by severity or table, pin a view you keep returning to, export the selection as CSV.

228 changes across 28 scans in the last 30 daysDev-Clean · simulated environment, sample data · counts summarize the window, rows load per selectionSecurity64Privilege granted24Role assigned12Principal created3Team member added7Column security grant added6Privilege revoked5Column security membership3Privilege scope changed2Role created2Power Pages5Site settings changed5Schema23Column added21Table added2Dependencies115Read added68Component added24Source modified10Findings21New finding12SECURITY COLUMN SECURITY GRANT ADDED · 6 SHOWNSUBJECTTARGETTRANSITIONIMPACTDETECTEDsim Bank Opssim_bankengagement.sim_estimatedvalueRead=Y · Create=N · Update=N708/7Local Identity Credentialscontact.adx_identity_usernameRead=Y · Create=N · Update=N558/3sim Permit Staffsim_permitapplication.sim_taxidRead=Y · Create=N · Update=N488/3

The three rows shown are column security grants on sim_bankengagement.sim_estimatedvalue and two other columns. Readers of the dependency analysis page have met that first column before: it is the one the worked chain derives from a public form. Here it is again, growing an access grant, which is the two surfaces answering each other: what writes a column, and who was just allowed to read it.

The row

Not just that it changed. What it changed from.

A change row carries the subject, the target, the date detected, and the transition itself: a column security grant arrives as Read=Y, Create=N, Update=N, a privilege scope change as the move it made, Local to Global. The before and after ride on the row because “something changed on this table” starts an investigation, while “this role gained org-wide read on this column on this date” ends one.

Findings in the ledger

Findings open, resolve, and sometimes come back.

A finding is a change like any other: the scan that surfaced it is on the row, the scan after the condition disappeared marks it resolved, and a condition that returns is marked regressed: resolved earlier, currently open again. Resolution is the scan observing the condition gone, not Pathix fixing anything; Pathix is read-only and remediates nothing. What the ledger adds is the history: the finding you cleared in April that reappeared in July is a different conversation than a finding you are seeing for the first time, and only one of those two stories survives in a tool that stores a status instead of a ledger.

NewA detector fired where it did not fire last scan.The finding opens, and the scan that surfaced itis on the row.ResolvedThe condition is gone from the environment. Therow stays in the ledger; nothing is edited away.RegressedResolved earlier, currently open again. The roundtrip is preserved, which is the difference betweena ledger and a status flag.EVERY ROUND TRIP IS APPENDED, NEVER EDITED
What the number means

Impact is prominence, and the product says so.

Change rows carry a number, and the temptation every tool gives in to is calling that number risk. Pathix labels it on the surface where it appears:

Impact is the affected node's graph prominence, frozen when the change was detected. It is not a risk ranking.

Graph prominence answers how central the changed thing is: how much writes it, reads it, sits next to it. A grant on a column half the environment touches deserves earlier eyes than the same grant on a column nothing uses, and that is all the number claims. The security verdict stays where it belongs, on findings with severities, and the two never blend into one score. Frozen at detection matters too: the number records how central the node was when the change landed, so it does not drift as the graph changes around it.

The ones nobody made

The diff has no opinion about who meant it.

Some of what the ledger records, nobody in your organization did. The platform grants privileges on its own; a solution import moves more than its release notes say; an upgrade widens a role. A diff against the last scan surfaces those exactly as it surfaces your own work, because it compares states rather than intentions. The sample window makes the point on Pathix itself: a product upgrade extended the Pathix Scanner role, and the grant shows up in the ledger like any other, impact number and all. Nothing is exempt, including us.

Where this fits

The backward-looking half of change safety.

Book a walkthrough →Read the sample report
© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π