1. Docs
  2. Identities

Identities

The people you administer: everyone in the places you look after, the roles they hold there, and what you can change about them.

Overview

An identity is one of your organization's end users: a nurse, a store manager, a field engineer. They are not administrators, and they do not sign in to Canopy. They sign in to your application, and Canopy answers what they are allowed to do there.

Nothing about a person is global to you. You see the ones in the places you administer, and someone administering a different part of the organization sees a different list of the same kind of people.

The directory

The directory is the list of those people, and it is where most work starts.

Each row is a person, with the roles they hold and where they hold them.Search and filter narrow the list; they do not widen it. Someone outside your places is not hidden by a filter, they are not there at all.Invitations that have been sent but not yet accepted are tracked separately, because a pending invitation is not yet a person.

A person's record

Opening a person shows what they hold and lets you change it: assign a role at one of your places, change the role or the dates on an assignment they already have, or remove one. Each of those is the assign capability rather than the reading capability, so an administrator can be able to see the directory in full and change nothing in it. Editing a person's name, resetting their sign-in, and deactivating them are not here: those are account-wide actions.

Active and deactivated

Every person is either active or deactivated, and the flag is account-wide rather than per place. Deactivating blocks them from signing in immediately, and it is deliberately not a deletion: their memberships, roles, and data stay exactly as they were, and reactivating restores access at once.

Deactivating stops new sign-ins. It does not tear down a session already in progress, which ends when it next tries to refresh. To cut someone off in the same moment, revoke their sessions as well.

The account-wide directory

Deactivating is one of a set of actions that belong to the account-wide directory rather than to your places. That directory covers every Environment, is a different capability, and is where someone with account-wide authority edits a person's name, sends a password reset, resends a verification email, revokes every session at once, resets multi-factor enrollment when a device is lost, and adds or removes a person's membership of an Environment. Resetting multi-factor removes every enrolled factor and invalidates their recovery codes, so the person enrolls again at their next sign-in.

Next Step

People arrive by invitation. Invitations covers sending one, what the recipient gets, and how to take it back.

Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.