What administrators can do
Every kind of administrator is described by the same list. A role is a bundle of capabilities, and granting the role is what confers them. This is the whole list, what each one lets someone do, and where it stops.
Overview
There is no second system of permissions for administrators. A regional manager who runs one branch, a delegate who handles the bill, and a developer who needs the Console all hold roles built from the same fixed list. Customers compose roles from it and never invent entries, because a capability only means something if Canopy enforces it.
This list is generated from the platform itself, so it cannot fall behind the product. The Workspace shows the same catalog on its own Capabilities page, with the roles in your account that carry each one.
How to read the list
Each capability records where it can be granted, which is what makes a grant unambiguous.
The capabilities
Grouped the way the role editor groups them.
Access
| Capability | What it allows |
|---|---|
| access.assignIn an environment | Grant a role to someone in your part of the organization, and take it back. You can only grant roles you have been permitted to grant, so this never becomes a way of giving someone more authority than you hold yourself. |
Account
| Capability | What it allows |
|---|---|
| account.manageAccount-wide | Edit the account's profile and general settings: its name, and the details that identify it. This does not include billing, and it does not include anything inside an environment. |
Activity
| Capability | What it allows |
|---|---|
| activity.viewIn an environment | Read the activity log for your part of the organization. You see what happened where you administer, which is less than an account-wide reader sees. |
Billing
| Capability | What it allows |
|---|---|
| billing.manageAccount-wide | Change the subscription, payment methods, tax details, and everything else about how the account pays. Includes everything the read capability allows. |
| billing.viewAccount-wide | Read invoices and billing history. No payment method is exposed and nothing can be changed. |
Danger zone
| Capability | What it allows |
|---|---|
| account.deleteAccount-wide, Owner only | Delete the account and everything in it. Never delegable: this one requires ownership, whatever role you hold. |
Governance
| Capability | What it allows |
|---|---|
| admin_governance.manageAccount-wide | Create administrator roles, decide which capabilities each one carries, and grant them to people. This is the capability that hands out authority, so treat it as the most consequential one on the list after deleting the account. |
| admin_governance.viewAccount-wide | Read the administrator roles that exist and see who holds each one. Enough to answer who can do what, without being able to change it. |
| administrators.manageAccount-wide | Invite an administrator, deactivate one, and remove one. Deciding which role they hold is a separate capability, so this alone lets you manage the roster rather than what the roster can do. |
| administrators.viewAccount-wide | Read the list of administrators and the access each of them holds. |
Identities
| Capability | What it allows |
|---|---|
| identities.manageAccount-wide | Create, edit, and deactivate end users anywhere in the account. The account-wide counterpart of administering people in one place. |
| identities.viewAccount-wide | Read the account-wide directory of end users: everyone in every environment, rather than only the people where you administer. |
| workspace_identity.inviteIn an environment | Invite a person into your part of the organization. They arrive where you administer, never above it. |
| workspace_identity.viewIn an environment | Read the people in your part of the organization: who is there, what roles they hold, and whether they are active. |
| workspace.administer_allAccount-wide | Administer people in every environment rather than in one. Granted instead of a per-environment assignment, for someone whose responsibility genuinely spans the whole account. |
Invitations
| Capability | What it allows |
|---|---|
| invitations.manageIn an environment | Resend and revoke invitations you can already see, within your part of the organization. Sending a new one is a separate capability. |
What an owner cannot delegate
One capability is never delegable to anyone, by any role: deleting the account. An owner can hand out everything else, including the ability to create administrator roles and grant them, which is itself a capability rather than a special status.
Next Step
Tell us how we can improve this guide.