72 deterministic finding types, 33 of them carrying a SOC 2, ISO 27001:2022, NIST 800-53, or CMMC and NIST 800-171 reference. The rest are environment-health findings and carry none. Every one is read from your own customization graph, plugins, roles, flows, Power Pages configuration and column security, and scored per instance in your environment.
Open findings across the environment, faceted by severity and category, each with a delta since the scan before. Findings on Microsoft-shipped and system-authored components are flagged as noise and hidden by default, so what you work is what your team actually owns.
Conditions Pathix detects deterministically. Most map to SOC 2, ISO 27001:2022, NIST 800-53, or CMMC; a few carry no control claim. Mappings are indicative: Pathix detects a condition relevant to a control, it does not certify, satisfy, or assess compliance on your behalf, and a finding, or its absence, is not an assessment outcome.
32 of them also carry a CMMC practice mapping. In total Pathix produces evidence for 4 of the 15 Level 1 practices and 15 of the 110 Level 2 practices, all carrying through Level 3. It is not a CMMC compliance platform and does not assess the rest of your environment; the Level 3 additions from NIST 800-172 are outside its scope. The full CMMC crosswalk →
Who really holds what, and where a change or a stolen credential quietly widens access, including the self-elevation paths.
The canonical "termination did not fully revoke" family: every residual path a disabled account leaves behind.
Where a column marked sensitive is misconfigured, exposed, or quietly copied past its own protection.
Where a change to sensitive data, or a failure in the code that touches it, leaves no trace.
How the environment reaches outside itself, and whether those connections are declared, authenticated, and encrypted. The code-level inventories are floors: only destinations written as literals are detectable, so a URL built at run time or a call behind a wrapper library is not counted.
What a Power Pages site's configuration grants to visitors, including ones who have not signed in. Pathix reads five of the six layers that decide site reach: web roles, table permissions, column permissions, page rules, and site settings. Whether the site itself is public or sits behind a sign-in wall is not readable by scan, so every finding here states what the configuration grants rather than confirming anything is public.
What your own AI is configured to do: who can talk to an agent, whose connection its tools run on, and which gated columns an assistant is set up to answer from. Read from configuration, never from conversations.
Broken, orphaned, looping or wasteful automation, and surfaces built on retired platform pieces. Often the reason a migration bid goes sideways. They are not compliance-control findings and carry no mapping.
Broken, orphaned, looping, or wasteful automation. Real environment-health value, but not evidence for a security control, and we label it that way on purpose.
Surfaces built on connectors and controls the platform has retired or moved on from.
Every scan runs these checks against your real Dynamics customization graph, ranked by severity, each with the principals it exposes and the control it answers to.