Practical method, written for people who already know Dynamics. Each guide shows the manual approach in full, including where it runs out. Nothing here needs Pathix to be useful.
The platform tracks declared metadata references, not logic. What that covers, what it cannot see, and a 90-second experiment to check it in your own environment.
The full manual method, worked against a real solution export: workflow XAML, flow definition JSON, canvas app PowerFx, plugin registrations, form scripts, and the two surfaces you cannot inspect by hand at all.
A diagnostic walkthrough: what audit attribution actually tells you, narrowing by deployment time and by what is bound to the table, the patterns usually responsible, and where the trail goes cold.
The four routes service accounts take to excess privilege, and how to find each one by hand in an environment you inherited. With the FetchXML.
Renaming, retyping and deleting. Why the logical name is fixed at creation, why the platform's delete check will not stop you breaking a plugin, and how to sequence a migration.
Microsoft's Dataverse MCP gives an agent data, schema and search. Where it stops on dependency questions, what read_query can still get you, and the two surfaces no Dataverse query reaches.
A dev-time linter and an environment-wide dependency graph answer different questions. Where the boundary sits, including what Solution Checker does better.
CMMC scope follows the data, not the product, and it resolves to the Dataverse environment underneath your apps. Separating the tenancy question from the system question, and inventorying the system by hand.
Microsoft shipped a real governance stack for Copilot Studio agents. All of it stops at the connector, and the questions below that line are the ones an audit asks. Why the ceiling is structural, and how to audit an agent by hand.
More on the way. If there is a question you keep having to answer the hard way, tell us and we will write it up: brian@pathix.app.