1. Docs
  2. What administrators can do

What administrators can do

Every kind of administrator is described by the same list. A role is a bundle of capabilities, and granting the role is what confers them. This is the whole list, what each one lets someone do, and where it stops.

Overview

There is no second system of permissions for administrators. A regional manager who runs one branch, a delegate who handles the bill, and a developer who needs the Console all hold roles built from the same fixed list. Customers compose roles from it and never invent entries, because a capability only means something if Canopy enforces it.

This list is generated from the platform itself, so it cannot fall behind the product. The Workspace shows the same catalog on its own Capabilities page, with the roles in your account that carry each one.

How to read the list

Each capability records where it can be granted, which is what makes a grant unambiguous.

Account-wide capabilities have no environment and no place. You either hold them everywhere or nowhere.Environment capabilities only mean something somewhere, so they are granted in one environment, optionally narrowed to a place and everything beneath it.A role carries capabilities of one kind, never both, because a mixed role would have nowhere to put its account-wide half when granted in an environment.

The capabilities

Grouped the way the role editor groups them.

Access
Capability What it allows
access.assignIn an environment Grant a role to someone in your part of the organization, and take it back. You can only grant roles you have been permitted to grant, so this never becomes a way of giving someone more authority than you hold yourself.
Account
Capability What it allows
account.manageAccount-wide Edit the account's profile and general settings: its name, and the details that identify it. This does not include billing, and it does not include anything inside an environment.
Activity
Capability What it allows
activity.viewIn an environment Read the activity log for your part of the organization. You see what happened where you administer, which is less than an account-wide reader sees.
Billing
Capability What it allows
billing.manageAccount-wide Change the subscription, payment methods, tax details, and everything else about how the account pays. Includes everything the read capability allows.
billing.viewAccount-wide Read invoices and billing history. No payment method is exposed and nothing can be changed.
Danger zone
Capability What it allows
account.deleteAccount-wide, Owner only Delete the account and everything in it. Never delegable: this one requires ownership, whatever role you hold.
Governance
Capability What it allows
admin_governance.manageAccount-wide Create administrator roles, decide which capabilities each one carries, and grant them to people. This is the capability that hands out authority, so treat it as the most consequential one on the list after deleting the account.
admin_governance.viewAccount-wide Read the administrator roles that exist and see who holds each one. Enough to answer who can do what, without being able to change it.
administrators.manageAccount-wide Invite an administrator, deactivate one, and remove one. Deciding which role they hold is a separate capability, so this alone lets you manage the roster rather than what the roster can do.
administrators.viewAccount-wide Read the list of administrators and the access each of them holds.
Identities
Capability What it allows
identities.manageAccount-wide Create, edit, and deactivate end users anywhere in the account. The account-wide counterpart of administering people in one place.
identities.viewAccount-wide Read the account-wide directory of end users: everyone in every environment, rather than only the people where you administer.
workspace_identity.inviteIn an environment Invite a person into your part of the organization. They arrive where you administer, never above it.
workspace_identity.viewIn an environment Read the people in your part of the organization: who is there, what roles they hold, and whether they are active.
workspace.administer_allAccount-wide Administer people in every environment rather than in one. Granted instead of a per-environment assignment, for someone whose responsibility genuinely spans the whole account.
Invitations
Capability What it allows
invitations.manageIn an environment Resend and revoke invitations you can already see, within your part of the organization. Sending a new one is a separate capability.

What an owner cannot delegate

One capability is never delegable to anyone, by any role: deleting the account. An owner can hand out everything else, including the ability to create administrator roles and grant them, which is itself a capability rather than a special status.

Next Step

Most of these capabilities are granted somewhere rather than everywhere. Places explains what that somewhere is and how far it reaches.

Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.