Build hierarchical access control, fast
Everything you need to model your organization, define roles and permissions, and integrate Canopy into your application, from your first login to enterprise-scale hierarchy.
Getting Started
2 guidesCore Concepts
11 topicsAccount Structure
How accounts, applications, and environments fit together.
Permissions
Define the actions your application supports.
Roles
Group permissions into roles you can assign.
Assign Roles
Hand out access one identity at a time, or in bulk.
Identities
Manage the end users who sign into your application.
Authentication
Hosted login or direct API: pick what fits.
Authorization Caching
Cache permission checks without serving a stale answer.
Multi-Factor Auth
Add a second factor to protect end-user sign-in.
Single Sign-On
Connect SAML and OIDC identity providers.
Hierarchy
Model real org structure with cascading access.
Organizations
Give each customer a tenant with its own members, roles, and sign-in policy.
Administration
14 topicsWorkspace
Read your own authority off the screen the Workspace opens on: where you administer, what you may do, and what you do not hold.
Signing In
Why one sign-in leads to the Console for one person, the Workspace for another, and a choice for a third.
Capabilities
Every administrator capability, what it allows, and where it can be granted.
Places
Regions, branches, teams. How Canopy knows which part of the organization is yours.
Identities
The people you administer, the roles they hold, and what deactivating one does.
Invitations
Bring someone into a place you administer, and manage the invitation afterwards.
Access
Give someone a role at a place, move it, or take it back.
Activity
What has happened in the places you administer, and how long it is kept.
Administrators
Who holds authority in the account, and how roles are composed and granted.
Billing
The subscription, the invoices, and who is allowed to change them.
Account
The account's own details, and where everything else lives.
Danger Zone
Deleting the account: what it removes, and who can do it.
Environments
Why the same organization exists more than once, and why your authority stops at one.
Roles
What a role is, and how an end user's role differs from an administrator's.
Developers
5 topicsSDKs and Libraries
Official client libraries for your stack.
API Keys
Create and scope API keys to a single environment.
OAuth Clients
Register applications and configure hosted login with PKCE.
Webhooks
Subscribe to events and keep your systems in sync.
Audit Log
Search and export an immutable record of every change.