By hand, it's in a dozen places: service endpoints and webhooks, custom connectors, connection references, dataflow queries and flow actions. And some addresses are written inside plugin code and form scripts, where no admin screen lists them.
Through your agent, one Pathix call lists what this environment is configured to call: three service endpoints, two webhooks, two custom connectors, three dataflows and thirty-four connection references. It also returns the addresses found as literals in code: a form script calls a scoring service, an agent reaches another environment, and a plugin calls a core banking host.
The plugin is the one from Ep. 03, and Pathix flags that it calls out over plain HTTP, from compiled code, to a destination registered nowhere. A webhook is registered on plain HTTP too, with no key, header or token, and nothing is bound to it, so it's also a candidate for cleanup.
The answer brings its own boundary: only destinations written as literals are found. A URL built at run time, an environment variable or a desktop flow is not in the list, and your agent is told so, in the same answer.
A read-only metadata scan of your environment that reads the logic inside the components: compiled plugins, flow definitions, workflow XAML and scripts.
How it works →A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.