Each customer account is fully isolated: its own hierarchy, roles, permissions, and identities. There's no shared state between tenants, so one customer's configuration can never affect another's.
Your customers define their own roles in Canopy. A healthcare customer and a logistics customer can run completely different permission models, in the same product, with no work from you.
Same product, two completely different permission models, defined entirely by the customers.
Give each customer's administrators access to manage their own users, roles, and hierarchy, scoped to their tenant. Support tickets for access changes disappear, because customers handle it themselves.
Any tenant can enable hierarchy within their own account, modeling departments, regions, and teams with scoped access. It happens entirely inside their boundary, with no platform changes from you.