1. Platform
  2. Use Cases
  3. Multi-Tenant B2B
Use Case Multi-Tenant B2B

Give every customer their own access control

Each tenant gets a fully isolated environment with its own hierarchy, roles, and permissions, configured independently, with no shared state. Multi-tenancy you don't have to build or maintain.

Isolated by default Customer-managed roles No shared state
AL
Acme Logistics
Tenant
Hierarchy 24 nodes
Roles 8
Permissions 32
Isolated
NH
Northwind Health
Tenant
Hierarchy 61 nodes
Roles 14
Permissions 47
Isolated
VF
Vertex Finance
Tenant
Hierarchy 38 nodes
Roles 11
Permissions 29
Isolated
Tenant isolation by default

Every account is a sealed environment

Each customer account is fully isolated: its own hierarchy, roles, permissions, and identities. There's no shared state between tenants, so one customer's configuration can never affect another's.

Own hierarchy, roles, permissions & identities
No shared state between tenants
One tenant's config can't affect another's
AL
Acme Logistics
account · acme-logistics
Isolated
Hierarchy
24
nodes across 4 regions
Roles
8
defined by this tenant
Permissions
32
custom catalog
Identities
1,204
users in this tenant
Sealed from every other account no cross-tenant access
Customer-managed roles

Each customer models their own world

Your customers define their own roles in Canopy. A healthcare customer and a logistics customer can run completely different permission models, in the same product, with no work from you.

Northwind Health
Healthcare
Their roles
Attending Physicianrx.approve
Charge Nursechart.edit
Records Clerkchart.view
Acme Logistics
Logistics
Their roles
Fleet Managerfleet.manage
Dispatcherroute.assign
Drivershipment.view

Same product, two completely different permission models, defined entirely by the customers.

Delegated administration

Your customers run their own access

Give each customer's administrators access to manage their own users, roles, and hierarchy, scoped to their tenant. Support tickets for access changes disappear, because customers handle it themselves.

Admins manage their own users & roles
Scoped strictly to their own tenant
Fewer access-change support tickets
Northwind Health / Admin JD Jane Doe · Owner
Manage Users
Invite, deactivate, assign
Define Roles
Their own role catalog
Edit Hierarchy
Departments & teams
View Audit Log
Their tenant's activity
Scoped to Northwind Health — no visibility into any other tenant.
Enterprise-ready hierarchy

When a tenant grows, their structure does too

Any tenant can enable hierarchy within their own account, modeling departments, regions, and teams with scoped access. It happens entirely inside their boundary, with no platform changes from you.

Per-tenant hierarchy — enabled inside their own account.
No platform changes — it all stays within their boundary.
NH Northwind Health TENANT BOUNDARY
acct: northwind-health HQ Cardiology Oncology Ward A Ward B Ward C Ward D

Ready to simplify access control?

Create an account and have authentication and hierarchical access control running today.