Canopy Settings
In Canopy Settings you configure your organization: company details, light and dark logo branding, and the sign-in and MFA methods allowed for your users.
Overview
Section titled “Overview”Settings is where you configure your own organization in Canopy. It opens at /settings and presents your organization’s configuration as a set of cards: company details and branding in one, sign-in and MFA rules in another.
Settings is organization-level configuration. It is distinct from the personal Profile menu in the top-right corner, which holds your own account details. See Profile vs Settings below.

Organization
Section titled “Organization”The Organization card holds your company details and branding, including separate light and dark logo uploads so your brand looks right in both themes.
To update your branding:
- Open Settings and find the Organization card.
- Edit your organization’s name and company details.
- Upload a light logo and a dark logo. Two uploads let Canopy show the right logo against light and dark backgrounds.
- Save the card to apply the changes across your organization.
Sign-in & MFA
Section titled “Sign-in & MFA”The Sign-in & MFA card controls how members of your organization authenticate. Here you choose which second-factor (MFA) methods your users are allowed to use when they sign in.
This is the organization-level counterpart to the per-user setup your members do themselves. Once you decide which methods are allowed here, each user enrolls their own second factor. See Setting Up Multi-Factor Authentication for the end-user steps in ThreoAI.
Allowed methods, migration, and cascade
Section titled “Allowed methods, migration, and cascade”Unchecking an MFA method stops new enrollments in it; users already enrolled keep working until you migrate them. Two controls apply when you save:
- On save, also - Migrate users off methods I just disabled: a one-time action that switches affected users to the first allowed method and emails them. It runs once, then resets.
- Cascade to child organizations: how the change propagates to child tenants.
- Don’t change child organizations (default) - children keep their own MFA configuration.
- Tighten - also remove your disabled methods from children, so stricter children stay stricter.
- Overwrite - force children to your exact list, wiping their existing configuration.
The safe default is Don’t change child organizations. Tighten and Overwrite reach into child tenants, so use them deliberately.
Profile vs Settings
Section titled “Profile vs Settings”Settings is organization-level: branding, company details, and the sign-in rules that apply to everyone in your organization. The Profile menu in the top-right corner is personal: your own account details and preferences. Change your organization’s configuration in Settings; change your own account from Profile.
Frequently Asked Questions
Section titled “Frequently Asked Questions”Where do I change my own profile? Open the Profile menu in the top-right corner. Settings is for organization-level configuration; Profile is for your personal account details and preferences.
What logo sizes and formats should I use? Upload a light logo and a dark logo so branding renders correctly in both themes. Use clear, appropriately sized image files for each; confirm the exact supported formats and dimensions in the upload control before you save.
Who can change the sign-in methods? The allowed sign-in and MFA methods are an organization-level setting, so they are changed by administrators in Settings, not by individual users.
Related
Section titled “Related”- Canopy Overview - the admin portal at a glance
- Managing User Permissions - roles and app permissions per user
- Setting Up Multi-Factor Authentication - the end-user MFA setup in ThreoAI
- Platform Admin - models, MCP, and skills for your organization

