Identities, Memberships & Assignments
How a person exists across three scopes (Account, Application, and Environment), and what "invited", "joined", and "assigned" each mean.
Overview
A person in Canopy exists at three independent layers, and a record at one layer doesn't imply the others. Understanding the split explains why the Console's setup guide and Environment cards say what they say: why someone you invited can show as pending, or why an Environment with members can still read as Awaiting users.
The three scopes
Account → Application → Environment
Each layer answers a different question about a person:
Because the layers are independent, "this person exists" and "this person can do something in this Environment" are different statements. The Developer Console reflects operational reality, not just whether a row exists somewhere.
Inviting vs. accepting
Sending an invite is not the same as accepting one
This is the most common point of confusion. The two actions create different things:
What the setup states mean
The setup guide and the Environment cards read from the same data, scoped to what's operationally true for the current Application and Environment.
An Environment card shows one of three states:
The two setup steps map onto the layers above: Invite Identities is Application-scoped ("has anyone joined this App?") and Assign Role is Environment-scoped ("can anyone be authorized in this Env?"). That's why inviting someone into one Application doesn't complete the step for another, and why assigning roles in staging doesn't carry into production.
Next step
Tell us how we can improve this guide.