MS tool to capture AD account domain privs?

Does MS make a utility/tool that can capture a domain account's access? In other words we have a programmer that is creating a PS script that will go out and capture information on user accounts and report. While we know domain admin privs will allow a "service" account to perform this task I was wondering if there was a tool of sorts that could show us exactly what permissions were needed so we could scale back access but at the same time not prevent the script from being successful. 


Ideas are appreciated. 

