1. Platform
  2. Features
  3. Identity Management
Feature Identity Management

Identities, and where they belong

Most systems manage identities. Canopy manages identities and where they exist in your organization. Create users, assign roles at specific hierarchy nodes, and control access, all in one place.

Provisioned & grouped Placed in your tree Contextual, not global
Identities Placed in your tree
Directory
DO
Dana Okafor
Regional Mgr
RT
Ravi Tan
Team Lead
MK
Mia Khan
Analyst
Organization tree
Acme · Root
East
West Region
SF
LA
DODana · here

Assign an identity to a node: permissions inherit and visibility scopes automatically.

Scoped to your organization structure

Identities don’t just exist. They belong somewhere.

Assign users at regions, departments, or teams. Permissions inherit automatically based on their position in the tree, and visibility is scoped to their assignment point. Access is always contextual, not global.

Assigned at regions, departments, or teams
Permissions inherit from their position
Visibility scoped to their assignment point
DO
Dana Okafor
Active
Assignment point
West Region
pinned
Inherited role
Regional Manager
cascades down
Visible scope
SFLA + region
scoped
Create & invite

Into your access model from day one

Create identities via API or send invitations by email. Optionally assign roles at specific nodes during creation. Invitees set their password and activate instantly.

1 Create

Via API or Console

Add a user and optionally assign a role at a specific node.

jordan@acme.com
Team Lead @ West / SF
Send invitation
2 Invite

Invitation by email

Invitees receive a link to set their password.

You're invited to Acme
Set your password to activate your account.
3 Activate

Instantly active

Placed into your access model, ready to work.

Account activated
Jordan is now Team Lead at West / SF.
Authentication lifecycle

We handle authentication. Your app never has to.

Canopy handles login, session management, password reset, email verification, and secure credential storage, so your application never stores passwords or manages authentication state.

Login

Hosted, secure sign-in.

Sessions

Managed automatically.

Password reset

Self-service flows.

Email verification

Confirmed on activation.

Credential storage

Secure, never in your app.

Your application never stores passwords or manages authentication state.
Activate & deactivate

Control access instantly

Deactivate a user and access is cut instantly: every permission check denies and no new tokens are issued. Reactivate when ready: all assignments and history are preserved, no cleanup required.

DO
Dana Okafor
Regional Manager · West
Sessions active live
Tokens valid issuing
Access granted scoped
DO
Dana Okafor
Deactivated · history kept
Access denied everywhere instant
No new tokens issued instant
Assignments & history kept preserved
Built for operators

Not just for developers

Customer success, ops, and IT teams can invite users, assign roles, manage access, and deactivate accounts, all through the Admin Workspace, no engineering involvement required.

People Search people… Invite
NameRoleNodeStatus
DO
Dana Okafor
Regional Manager West Region Active
RT
Ravi Tan
Team Lead SF Office Active
JL
Jordan Lee
Analyst LA Office Invited
MK
Mia Khan
Auditor East Region Deactivated
Invite users Assign roles Manage access Deactivate accounts No engineering required
Use Canopy for identity, or bring your own

Adopt it based on your architecture

Use Canopy for full identity management and authentication, integrate your existing auth system, or use Canopy for authorization only.

Full stack

Full identity management

Use Canopy for full identity management and authentication.

Identity + Authn + Authz

Integrate your auth

Integrate your existing authentication system with Canopy.

Your IdP + Canopy

Authorization only

Use Canopy for authorization only, and keep your own identities.

Authz only

Ready to simplify access control?

Create an account and have authentication and hierarchical access control running today.