Admin, member, viewer. Live in hours.
Your own permissions, environment-wide.
Departments & regions. No migration.
Register an OAuth application, redirect users to Canopy's hosted login, and receive signed JWTs. Email verification, password reset, and session management are all handled for you.
Most early-stage products need simple roles: admin, member, viewer. Canopy's flat RBAC gives you exactly that: environment-wide roles with custom permissions. No hierarchy overhead until you need it.
When your enterprise customers need departments, teams, and regional access, enable hierarchy. Existing roles and assignments carry forward: no migration, no breaking changes. Your code doesn't change.
Your code doesn't change. Existing roles and assignments carry forward automatically.
Every account is fully isolated. Your customers' data never intersects, and each tenant can configure their own roles and permissions independently.