Feature Security & Compliance

Always know what happened

When something goes wrong with access control, the first question is always 'what happened?' Canopy records every security-sensitive action automatically: who did it, what changed, and when. No instrumentation required.

Every action logged Full context captured Zero instrumentation
Audit log · Acme Holdings LIVE
Dana Okaforidentity.createdjordan@acme.com
12:04:01 · 10.0.4.21
Dana Okaforassignment.createdRegional Manager → west/sf
12:04:01 · 10.0.4.21
API key · ci-botnode.createdwest/san-diego
11:58:33 · ci-bot
Sofia Marininvite.createdtaylor@acme.com
11:50:12 · 10.0.4.52
Priya Nairapi_key.revokedlegacy-export
11:42:09 · 10.0.4.88
Built for complex access control

Hierarchical access has complexity flat systems don't

Permissions inherit across nodes. Roles are assigned at different levels. Access changes ripple through the tree, and the impact isn't always obvious. Audit logs make that complexity traceable: every change, every actor, every affected resource.

Permissions that inherit across nodes
Roles assigned at different levels
Changes that ripple through the tree
Acme Root
East
Westrole changed
SF
LA
San Diego
Phoenix
One role change at West cascaded to 3 child nodes, all captured in a single, traceable entry.
Debug access issues

No guessing. No reproducing. Just look at the log.

When a user reports they can't access something, audit logs show exactly what changed and when. Trace the chain: who removed the role, when the node was moved, which API key made the call.

“Why can't Mia approve invoices anymore?”
Reported 12 minutes ago · West / SF
1
Who changed her role?
API key · hr-sync triggered assignment.removed removed Regional Manager from Mia.
Jun 24 · 09:14
2
Was a node moved?
Dana Okafor triggered node.moved moved SF under a new parent.
Jun 23 · 16:02
3
Which call did it?
Both originated from the hr-sync key during the nightly HR sync.
Jun 24 · 09:14
Root cause found in under a minute — the HR sync unassigned her role after the node move. No reproducing required.
Audit-ready evidence

The evidence is already there

Every entry includes timestamps, actor identification, and resource details. Whether you need SOC 2 evidence, internal security reviews, or incident response records, the data is already captured.

Precise timestamps: every action carries a UTC timestamp to the second.
Actor identification: user, API key, or integration, always attributed.
Resource details: exactly which node, role, or identity was affected.
audit_entry
9c2f1a47-3e08-4b6d-bf21-7a4e9c1d2b3a
IMMUTABLE
action
assignment.created
actor
dana@acme.com · user
resource
role:RegionalManager → west/sf
timestamp
2026-06-24T12:04:01Z
outcome
success
correlation_id
a71f3e02-9c44-4e15-b8d0-2f6a1c3d4e0b
SOC 2 evidence Exportable Queryable
Automatic and complete

You don't configure what gets logged

Canopy records every security-sensitive operation by default, comprehensive and automatic. No opt-in toggles, no manual instrumentation. If it affects access control, it's in the log.

No instrumentation

Nothing to wire up in your application. Logging happens at the platform layer.

On by default

No opt-in toggles. Every account captures the full record from day one.

Comprehensive

If an operation affects access control, it lands in the log, every time.

Coverage across the system

Everything that impacts access, in one place

Recorded consistently, whoever (or whatever) performed the action.

Roles & permissions

Role assignments and permission changes across every node.

Identity lifecycle

Creation, activation, deactivation, and profile changes.

Hierarchy updates

Nodes added, moved, renamed, or removed from the tree.

API keys & integrations

Key creation, rotation, revocation, and integration changes.

Invitation workflows

Invites sent, accepted, resent, or revoked.

Authentication events

Sign-ins, session changes, and credential operations.

Ready to simplify access control?

Create an account and have authentication and hierarchical access control running today.