A plugin step that always runs as the same named user
What it is
Plugin step always runs as one fixed user account.
Why it matters
Every change the step makes is attributed to one account regardless of who triggered it, obscuring who really acted, and it breaks the day that account leaves.
Find it yourself
Same list as above, but read it for steps impersonating an active named person rather than a service account. This is the one that quietly corrupts your audit trail: every write the step makes wears that person's name.
How to fix it
Confirm the impersonation is intentional and points at a dedicated service account, not a person's login.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AU.L2-3.3.2 (Level 2: ensure the actions of individual users can be uniquely traced to them), for the Dataverse system in your assessment scope. Every write the step makes is attributed to one named person who did not make it. The audit trail is not merely incomplete here, it is confidently wrong about who acted.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.