A Power Pages site (the product formerly named Power Apps portals) decides that across table permissions, web roles and site settings, in surfaces that do not talk to each other and mostly cannot be reviewed on one screen. Pathix reads them as one model, then follows the chain from a page through its form to the columns underneath, so the question stops being which pages are open and becomes which columns an open page touches.
Pages, templates, snippets, forms and lists, alongside the web roles and access rules that gate them. The figures below come from a scan of the Microsoft out-of-the-box scheduling template, which is why they can be published at all.
That last figure is the one worth being precise about, so the rest of this page is largely about what it does and does not mean.
Reach is not one setting, it is a stack, and a scan can read all of it but the top. So Pathix reports what the configuration grants and says plainly which layer it could not see. A site nobody can reach makes every finding on this page moot, and Pathix will not pretend otherwise to make the number look worse.
Every Power Pages finding Pathix raises inherits that bound. The wording on each one is a statement about configuration, never a verdict that data is public, and that is a deliberate limit rather than a hedge: see the findings themselves.
One page of the console, scanned from the Microsoft out-of-the-box scheduling template, unedited: the counts along the top, the badge on every page in the tree, the assembly of the selected page, the walk through its form steps, and the rule that decides who gets in. The sections that follow are this screen redrawn a piece at a time, because at page width the pieces are readable and the whole is not.
Access rules inherit down the tree, so the page you are looking at is rarely the page that granted anything. Pathix resolves the inheritance and puts the answer on every node at once, which turns a per-page investigation into a page you can read.
An advanced form is a sequence, and each step loads a model-driven form of its own. Pathix keeps the whole walk on one graph, including branches, so a step that quietly reads more than the step before it is visible next to the ones that do not.
A page embeds an advanced form, the form binds its steps, and the steps read and write a real table. Pathix walks that chain end to end and terminates it on the columns, ranked by salience, so you are looking at column names rather than at a page count.
Which is where the earlier caveat earns its keep. This resolves what the configuration connects to what. It is the strongest form of the question you can answer without issuing a request, and Pathix does not issue one.
Every rule that applies to a page is listed with its right, its scope and the web roles it names. An answer you cannot trace back to a rule is an answer you cannot act on, and it is the reason "authenticated" is worth reading twice on a site where four roles satisfy it.
These run without being asked for, alongside the rest of the catalog. Each links to what it detects, how to check it by hand, and the bound on what it claims.
Six of them also produce evidence for CMMC AC.L1-3.1.22, the practice about what a publicly accessible system is allowed to hold.
A walkthrough runs the real console on sample data, so you can walk a site tree and follow a page down to its columns before anyone touches your environment.