PathixDataverse Forensics
Risk · security analyst & CISO

Find the risk in your config.
Then prove it's handled.

Every scan runs a security audit against your real Dynamics customization graph: a role shared between humans and integrations, an application user that can write the security model. Each finding carries a severity, the principals it exposes, and the control it answers to, and you work it from open to mitigated without leaving Pathix.

Book a demoSee the whole picture

This is the risk Pathix finds in your environment. For how Pathix itself is built and secured, see Security →

The console

Every finding in one place, ranked.

A scan lands in the console as one ranked list you work top down: a privileged role shared between a human and an integration, a disabled user that still holds its roles, a column secured with no profile that can read it. Each finding can be assigned and triaged with a captured reason, and an environment-wide decision log records who decided what and when.

Pathix security findings console: open findings faceted by severity and category, a privileged shared role, a disabled user retaining its roles, and a field secured with no profile grants, each with a since-last-scan delta.
Signal over noise

A first scan that doesn't bury your team.

A scan on a ten-year-old environment surfaces a lot at once. Findings on Microsoft-shipped and system-authored components are flagged as noise and hidden by default, so you see what your team owns rather than thousands of platform artifacts. What remains groups by rule and sorts by severity. When a view is hiding anything it says so, and nothing is suppressed silently.

When a finding is a known, accepted risk, an admin accepts it with a written justification. It leaves the working view and lands in an append-only decision log, and stays accepted when the scan re-detects it, so the call is made once. An entire finding type can be tuned out across the environment, reversibly, without losing the record. Every acceptance and suppression is captured with who, when, and why: an auditable risk-acceptance trail that maps cleanly to your exception-management controls.

A single finding

Severity, the fix, and the control it answers.

Open a finding and Pathix explains the risk in plain language, scores its severity, names the principals affected, and gives concrete remediation steps. Each one maps to the control it satisfies, so the work stays legible to a security review. Between the status workflow, the captured reason and the activity log, the decision and who made it are recorded by the time anyone asks.

Control mappings (SOC 2 CC6.3, ISO 27001 A.8.2 and the like) are shown where a finding maps cleanly. Pathix surfaces and tracks the risk; it is not a substitute for your audit or your auditor.

A single Pathix finding, Privileged role shared between humans and integrations, rated High: the affected role, a plain-English explanation, remediation steps to split the role into human and integration variants mapped to least-privilege controls (SOC 2 CC6.3, ISO 27001 A.8.2), a risk breakdown of base severity High and 20 principals affected, a status workflow of open, reviewing, accepted risk, and mitigated, a reason field, and an activity log of who changed the status and when.

With AI on: hand a finding to an agent over the Pathix MCP and it triages the risk, drafts the remediation, and checks whether your last change actually cleared it.

Finding types

One type, every instance, the trend.

Every finding rolls up to its type, and the type page is its definition: what the risk is, the remediation that clears it, and every instance in your environment with the principals each one exposes. The instances-per-scan trend tells you whether you are closing this class of risk or opening new ones faster than you fix the old.

A Pathix finding type, Shared Role, tagged ROLE at High severity: the definition with its SOC 2, ISO 27001 and NIST control mappings, the remediation that splits the role in two, 3 open instances across 26 affected principals, one new since the last scan, an instances-per-scan trend across the last eight scans, and an instances table listing each affected role with its assignee and a status of open or reviewing.
Why it catches what others miss

Generic scanners don't speak Dataverse.

The risks that matter in Dynamics live in its own security model: roles, teams, the business-unit hierarchy, column-level security, application users, and the privileges the platform grants quietly on its own. Pathix reads all of it from the same deterministic graph that traces your dependencies. A role widened across a human and an integration gets flagged: an exposure an IAM tool pointed at the tenant never sees.

And Pathix never calls an environment clean without showing you what it did not scan. No findings is not the same as no problems, and the product says so out loud. One click turns the open findings into a printable Environment Report, the leave-behind for an assessment.

See the full catalog: every check Pathix runs →

See your risk in a real environment.

A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.

Book a demo
© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π