In Dynamics, column security shows you the lock: the profile, what it allows, who holds it. It doesn't show where the value goes next, and a flow, a workflow, a column mapping or a calculated column can copy it somewhere the lock doesn't reach.
Taxpayer ID is under column security, and two profiles grant it: the intake service can read and write it, and Permit Staff can only read it. A service account holds the intake profile, the reviewers team holds Permit Staff, and no per-record shares were found.
A flow that runs when a permit is added writes the application number and the Taxpayer ID to Applicant Reference, a column that is not secured. Pathix flags it as High: anyone who can read the reference can read the Taxpayer ID, profile or not. Fixing the flow doesn't reach back, so values it already copied stay readable until someone clears them.
Pathix checks who holds the profile, per-record shares, and copies made by flows, workflows, column mappings and calculated columns. System Administrators bypass column security, and Pathix says so. No shares found is what the scan measured, not proof there are none.
One Pathix call returns the profiles, and who holds them. Another returns the finding, with both columns. The Dataverse MCP can read the profiles. The copy lives in a flow definition, one of many to open.
A read-only metadata scan of your environment that reads the logic inside the components: compiled plugins, flow definitions, workflow XAML and scripts.
How it works →A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.