GrantPath helps you see who has access to what across IAM, Active Directory, and file servers. It shows why access exists and what changes if you remove it. Use it to review permissions before you make changes.
- Open the GrantPath releases page.
- Find the latest version near the top of the page.
- Download the Windows file for your system.
- Open the file after the download finishes.
- Follow the on-screen steps to install or run GrantPath.
- If Windows asks for permission, choose Yes.
GrantPath runs on modern Windows systems and works best on:
- Windows 10 or Windows 11
- 4 GB of RAM or more
- 500 MB of free disk space
- A stable network connection for access data
- Permission to read the systems you want to review
For larger environments, 8 GB of RAM or more can help with faster results.
GrantPath gives you a clear view of access across your environment. It helps you:
- See who can reach a user, group, folder, or resource
- Trace why access exists
- Spot inherited permissions
- Review access paths before removal
- Compare current access with expected access
- Prepare access reviews with less manual work
It is built for teams that need a simple view of complex permission data.
- Start GrantPath on your Windows PC.
- Connect it to the systems you want to review.
- Choose the account, group, folder, or app you want to inspect.
- Let GrantPath scan the access paths.
- Review the results in the main view.
- Open a path to see why access exists.
- Check what will change before you remove access.
- Export or share the results with your team if needed.
GrantPath can help you review:
- Active Directory users and groups
- File server permissions
- Nested group access
- Direct and inherited permissions
- Account-to-resource links
- Access chains that are hard to see by hand
This helps when you need to answer basic questions like:
- Who has access?
- Why do they have it?
- What breaks if we remove it?
Use GrantPath to review who has access to a shared folder, app, or service account path.
Find access that no longer fits current roles and check the effect before removal.
Look for broad group access, stale permissions, or unexpected access paths.
See who can read, change, or own files and folders.
Track how access flows through groups and directory roles.
GrantPath reads access data, builds a graph, and shows the links between users, groups, and resources. This graph view makes it easier to follow access paths that are hard to track in a list.
Instead of checking one permission at a time, you can see the full chain:
- A user belongs to a group
- The group has access to a folder
- Another group adds more access
- A direct rule grants the final permission
This helps you explain access in plain terms.
- Graph view for access paths
- Support for IAM and Active Directory review
- File server permission analysis
- Clear explanation of why access exists
- View of what changes when access is removed
- Fast search and filtering
- Self-hosted setup
- Simple interface for non-technical users
- Built for access intelligence and entitlement review
When you open GrantPath for the first time:
- Let it finish loading before you click around
- Start with one user, group, or folder
- Use search to find a known account
- Open one access path at a time
- Check the change view before you remove anything
- Save your work if the app gives you that option
GrantPath needs read access to the systems you inspect. It does not need you to change permissions right away. Start with read-only access if your environment supports it.
If you plan to review Active Directory or file server data, use an account with the right view access in your network.
- Open GrantPath.
- Connect to Active Directory and a file server.
- Search for a user who should not see a folder.
- Open the access graph.
- Check which group gives that user access.
- Review the reason for that access.
- Look at the change view.
- Remove the path only after you confirm the impact.
GrantPath can help you share findings with others on your team. Use the results to:
- Show why access exists
- Support access review work
- Document permission changes
- Explain what changed after a cleanup
- Help managers approve removals
If GrantPath does not start:
- Check that the download finished
- Run the file again
- Make sure Windows did not block the app
- Try a newer Windows version if your system is old
If data does not load:
- Check your network connection
- Confirm you used the correct account
- Make sure the source system allows reads
- Try one smaller target first
If the view looks empty:
- Search for a known user or folder
- Confirm the source has data to scan
- Refresh the view after the scan completes
- Start with one system at a time
- Review access before you remove it
- Use the graph to trace nested groups
- Keep notes on why access exists
- Check inherited permissions before making changes
- Reuse the same review steps for each folder or app
access-intelligence, access-review, authorization, cybersecurity, entitlement-intelligence, entitlement-management, explainability, fastapi, graph, iam, react, self-hosted
If you need the latest build, visit the GrantPath releases page to download and run the latest Windows file
GrantPath