Assign an identity to a node: permissions inherit and visibility scopes automatically.
Assign users at regions, departments, or teams. Permissions inherit automatically based on their position in the tree, and visibility is scoped to their assignment point. Access is always contextual, not global.
Create identities via API or send invitations by email. Optionally assign roles at specific nodes during creation. Invitees set their password and activate instantly.
Add a user and optionally assign a role at a specific node.
Invitees receive a link to set their password.
Placed into your access model, ready to work.
Canopy handles login, session management, password reset, email verification, and secure credential storage, so your application never stores passwords or manages authentication state.
Hosted, secure sign-in.
Managed automatically.
Self-service flows.
Confirmed on activation.
Secure, never in your app.
Deactivate a user and access is cut instantly: every permission check denies and no new tokens are issued. Reactivate when ready: all assignments and history are preserved, no cleanup required.
Customer success, ops, and IT teams can invite users, assign roles, manage access, and deactivate accounts, all through the Admin Workspace, no engineering involvement required.
| Name | Role | Node | Status | |
|---|---|---|---|---|
DO Dana Okafor dana@acme.com | Regional Manager | West Region | Active | |
RT Ravi Tan ravi@acme.com | Team Lead | SF Office | Active | |
JL Jordan Lee jordan@acme.com | Analyst | LA Office | Invited | |
MK Mia Khan mia@acme.com | Auditor | East Region | Deactivated |
Use Canopy for full identity management and authentication, integrate your existing auth system, or use Canopy for authorization only.
Use Canopy for full identity management and authentication.
Integrate your existing authentication system with Canopy.
Use Canopy for authorization only, and keep your own identities.