Skip to content
synthreo.ai

Managing Permissions

How to manage user permissions in Synthreo: grant, modify, and revoke application access for ThreoAI, Builder, and Canopy across parent and child tenants.

This guide explains how to manage application permissions for users in Synthreo’s Canopy portal. Permissions control which Synthreo tools a user can access.


Each user can be granted access to one or more Synthreo applications:

PermissionWhat It Grants
ThreoAIAccess to the AI chat interface, Experts, Agents, and Projects
BuilderAccess to the AI agent workflow canvas, node configuration, and testing
CanopyAccess to the admin console for user and customer management

Permissions are managed on the user’s own detail page, not inline in the list. Click the user’s row in User Management to open it - the whole row is the link; there is no expand arrow and no menu button.

The detail page is organized into cards:

  • Account Details - the user’s first and last name (editable), plus read-only Created, Last Access, MFA Method, and User ID.
  • Security - Reset MFA, Send Password Reset, Update Email (which uses a confirmation-link flow), and Resend Invitation (shown only while the user has not finished setup).
  • Access and Permissions - the user’s application permissions, managed through an Add, Edit, and Delete permission dialog. Each permission entry has an Application Type, Region, Account, Role, and an active toggle.
  • Danger Zone - Remove User, which deletes the account.

The sections below cover viewing and changing those permissions in more detail.


  1. Go to https://canopy.synthreo.ai
  2. Click User Management in the left sidebar
  3. Locate the user in the list
  4. Click their row to open the user detail page
  5. Read their current application permissions in the Access & Permissions card
  1. Click Customers in the left sidebar
  2. Click the customer’s row to open their detail page
  3. Go to the Users tab
  4. Click the user’s row to open the user detail page, then read the Access & Permissions card

To grant a user access to an additional application:

  1. Navigate to the user (parent tenant or child customer - see above)
  2. Open the Access & Permissions card
  3. Add a permission using the card’s controls
  4. Select the application to grant (Builder or Canopy; ThreoAI is already present on every user)
  5. Assign the appropriate role for that application:
    • Builder: Account Owner, Sysadmin, Admin, FPU, FS RPU, or DCS OPU
    • ThreoAI: Admin (only role available)
    • Canopy: Owner or Admin
  6. Save the changes

The user will have access to the new application on their next login.


To revoke a user’s access to an application:

  1. Navigate to the user’s permission list
  2. Locate the permission you want to remove
  3. Use the delete or toggle control to remove the permission
  4. Confirm the removal

To update the role assigned within an application permission:

  1. Navigate to the user’s permission list
  2. Locate the permission entry for the application you want to update
  3. Click Edit or the role control next to the permission
  4. Select the new role from the dropdown
  5. Save the changes

The role change takes effect on the user’s next login or page refresh.


If a user cannot sign in, you can trigger a password reset for them from User Management:

  1. Locate the user in the list (for a child-customer user, open the customer’s detail page and use the Users tab)
  2. Use the Send password reset action for that user

Canopy emails the user a link to set a new password. For a locked-out second factor, see Resetting MFA for a User.


Permissions are scoped to the tenant where they are assigned:

  • A permission granted at the parent tenant level applies to the parent tenant only
  • A permission granted at a child customer level applies to that child customer only
  • Permissions do not automatically cascade from parent to child tenants

IssueCauseFix
Add Permission button not visibleInsufficient administrative roleVerify your account has Owner or Admin role in Canopy
Permission change not reflected for the userUser is still logged in with a cached sessionAsk the user to log out and log back in to pick up the updated permissions
Cannot remove a permissionNo confirmation dialog appearingEnsure pop-ups are allowed for the Canopy site
User removed from all permissions but account still existsPermissions and accounts are separateThe account remains until explicitly deleted; re-grant permissions to restore access

Can I grant Builder permission to a user without granting ThreoAI? Every user has ThreoAI as their locked base permission, so it is always present. You can grant Builder (and Canopy) on top of it independently, but you cannot give someone Builder-only access with ThreoAI removed.

What role should I assign when granting Builder access to a new user? For most users, start with Full Power User (FPU). This gives broad build-and-test access without the ability to manage team members or billing. See Roles & Permissions for the full role comparison.

Does the user need to do anything after permissions are changed? The user should log out and log back in to pick up any permission changes. Changes to an already-open session may not take effect until the next login.

Can I grant Canopy access to a child-customer user? Yes. Navigate to the child customer’s user list, expand the user’s permissions, and grant Canopy access. The user will then be able to administer their own child tenant.