By hand, a site is hundreds of records: pages, templates, snippets, forms, lists, web roles, table permissions and page rules. And the Liquid that ties them together is read one template at a time.
Every page in the site tree is tagged ANON or AUTH: open to anyone, or to signed-in visitors only. Select one and Pathix shows why. Book an Appointment is for signed-in visitors, because the access rule attached to it admits any authenticated visitor. Rules inherit down the tree.
Book an Appointment is a page template and a multistep form: seven steps, each loading a model-driven form. In the graph, step six writes the appointment request, and a plugin reads its start time and creates an engagement. That's the trail Ep. 03 followed.
Here the site is configured to give anonymous visitors eight table permissions on six tables, all Global, and three of them can delete. Some of that is expected: a booking site can list its services for anyone, so the read finding is accepted with a reason, and the write finding stays open. The one thing Pathix can't read is whether the site is public.
One Pathix call returns which site audiences reach a table, and the forms and lists bound to it. With the Dataverse MCP alone, your agent reads the table permissions, web roles and site settings, and joins them itself.
A read-only metadata scan of your environment that reads the logic inside the components: compiled plugins, flow definitions, workflow XAML and scripts.
How it works →A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.