Every offboarding ticket and every access review comes down to this question. In Dynamics, the answer is spread out, and none of the screens adds it up.
Roles on the user record, roles on every team they're in, the hierarchy they sit in. None of them adds it up, so a review sees "Roles: 0" and decides everything's fine.
The marketing connector from Ep. 02 has no direct roles, but through the sales team it can create, read and write accounts, and the row names the team it came through. In the position hierarchy it sits one level above the ERP sync, so it inherits the sync's read and write on accounts. That's two paths to accounts, and neither one is on the connector's own record.
Dave Morgan is disabled, and his record still lists two roles, one of them the credit writer from Ep. 02. He's also on the sales team, which holds the same role, so removing his direct role leaves it in place through the team: that's why Pathix keeps two lists. It's reach, not activity: Pathix never reads sign-ins, or which records anyone opened.
One Pathix call returns what this principal can reach, and the path to each: direct, through a team, or the hierarchy. With the Dataverse MCP alone, your agent assembles that from roles, teams and positions.
A read-only metadata scan of your environment that reads the logic inside the components: compiled plugins, flow definitions, workflow XAML and scripts.
How it works →Or check it by hand: the integration account problem→All questions →
A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.