Skip to content
synthreo.ai

Roles & Permissions

Synthreo roles reference - what each Owner, Admin, Builder, and End User role lets a person do in Canopy, Pylon, Threo, and Hub, and how the roles differ.

A role decides what a person can do inside one application. Everyone holds one role in each application they can use. To grant an application and choose the role, see Managing Permissions.


Every application’s roles fit the same four levels:

LevelWho it is for
OwnerThe person a customer account is created for. Has everything an Admin has, plus the owner flag (below)
AdminPeople who run the account: they manage users, settings, and everything shared across the company
BuilderThe people doing the work. They build and run their own work and use what is shared with them, with no account-wide settings
End UserThe most limited role in an application

Each application’s role names for those levels:

LevelCanopyPylonThreoHub
OwnerOwnerAccount HolderCustomer AdminAccount Holder
AdminTenant Admin, Tenant Admin (no impersonation)Pylon Admin--
Builder-Builder--
End User-End UserMemberMember

An Owner role carries an owner flag. An Admin administers the same things an Owner does, with two differences:

  • Giving roles. You can give someone a role only if your own role in that application includes everything the new role can do. An Owner can give any role in their application, except a Hub persona role they do not hold themselves (see Hub Roles).
  • Signing in as an owner. To use Sign In As on an owner in your own company, you must hold the owner role in that same application yourself.

The owner role itself is the exception to the first rule: anyone who holds a role with permissions in that application can give it, and more than one person can hold it.


Canopy has three roles. All three administer your organization and the customers under it: people, customers, company details, billing details, and branding.

RoleWhat it covers
OwnerFull administration, plus the owner flag
Tenant AdminFull administration, including Delegate Login and Sign In As
Tenant Admin (no impersonation)Full administration and Delegate Login, without Sign In As

Delegate Login lets you work inside a customer below yours. Sign In As lets you act as one named person there, and signing in as a Threo user also needs that person’s consent. See Sign In As and Delegate Login in Canopy.

PermissionOwnerTenant AdminTenant Admin (no impersonation)
Add, edit, and remove peopleYesYesYes
Create, manage, and delete customers below yoursYesYesYes
Edit company details, billing details, and brandingYesYesYes
Work inside a customer below yours (Delegate Login)YesYesYes
Act as a named person there (Sign In As)YesYesNo
Give someone the Owner roleYesYesYes
Give someone the Tenant Admin roleYesYesNo

In your own company, nobody can Sign In As someone in Canopy itself. Signing in as an owner of another application depends on your role in that application, not your Canopy role (see What the owner flag adds).

Nobody can delete their own company or remove themselves.


RoleLevelWhat it covers
Account HolderOwnerEverything Pylon Admin has, plus the owner flag
Pylon AdminAdminRuns the account: sees every automation, makes automations company-wide and shares them, chooses who they run as, and manages connectors, skills, variables, templates, and Teams settings for the whole company
BuilderBuilderBuilds, tests, publishes, and schedules their own automations, and uses anything shared with them
End UserEnd UserBuilds and runs their own automations and uses what is shared with them, but cannot schedule workflows, add webhooks to them, or use company variables or shared agent memory

Inside Pylon, Account Holder and Pylon Admin have the same access. They differ only by the owner flag.

PermissionAccount HolderPylon AdminBuilderEnd User
Build and edit their own agents and workflowsYesYesYesYes
See and edit every automation in the accountYesYesNoNo
Schedule a workflow or give it a webhookYesYesYesNo
Use shared company variablesYesYesYesNo
Change shared company variables on the Variables pageYesYesNoNo
Change shared company variables from inside an automationYesYesYesNo
Manage shared agent memoryYesYesYesNo
Install a connector for the whole companyYesYesNoNo
Add a skill for the whole companyYesYesNoNo
Make an automation company-wide and share itYesYesNoNo
Choose who an automation runs asYesYesNoNo
Publish and deploy templatesYesYesNoNo
Change the company’s Teams notification settingsYesYesNoNo

RoleLevelWhat it covers
Customer AdminOwnerManages Threo for the whole company: company connectors, company skills, and other people’s activity
MemberEnd UserUses Threo with their own connectors, skills, and Experts

The person a customer is created for is its Customer Admin. Everyone added after that is a Member. Canopy has no Edit action on a Threo permission; to make someone a Customer Admin, contact Synthreo support.

PermissionCustomer AdminMember
Connect their own connectorsYesYes
Install a connector for the whole companyYesNo
Choose which connector tools the whole company may useYesNo
Add their own skillsYesYes
Add and manage skills for the whole companyYesNo
Manage other people’s skills and shortcutsYesNo
See other people’s profiles and activity, including in customers below yoursYesNo

You give someone a Hub role in Canopy with Add Permission on their user, choosing Hub as the Application Type. Hub is listed there only when the customer has a Hub account. See Managing Permissions.

RoleLevelWhat it covers
Account HolderOwnerAdministers the organization’s Hub. On a partner (MSP or reseller) organization, it opens the partner portal
MemberEnd UserLearner access: Academy, documentation, and notifications

Synthreo also sets up five persona roles where they fit. Each fits one kind of organization, and the Role list only offers a persona that fits the customer:

RoleFitsWhat it covers
SalesSynthreoCRM, customers, prospects, Academy, files, documentation, and feedback
Professional ServicesSynthreoDelivery (projects, tickets, and time), motions, customers, files, documentation, feedback, and setting up new customers
Partner PortalPartner (MSP or reseller) organizationsChannel CRM, delivery for its own customers, customers, client usage, Academy, files, documentation, and feedback
Partner TechnicianPartner (MSP or reseller) organizationsLearner access: Academy, notifications, and documentation
End CustomerEvery other organizationThe customer portal, Academy, documentation, and notifications

A persona role’s access comes from its name. To give someone a persona, you must hold that persona yourself, unless you are Synthreo.

An Account Holder on a partner organization gets the same access as Partner Portal, plus Billing and setting up new customers. A Member gets the same access as Partner Technician.

The table shows what each role sees in the Hub menu.

PermissionAccount Holder (partner organization)Account Holder (any other organization)MemberSalesProfessional ServicesPartner PortalPartner TechnicianEnd Customer
DocumentationYesYesYesYesYesYesYesYes
NotificationsYesYesYesYesYesYesYesYes
AcademyYesYesYesYesNoYesYesYes
BillingYesYesNoNoNoNoNoNo
FeedbackYesYesNoYesYesYesNoNo
Set up new customersYesYesNoNoYesNoNoNo
Customer listYesNoNoYesYesYesNoNo
FilesYesNoNoYesYesYesNoNo
CRMYesNoNoYesNoYesNoNo
DeliveryYesNoNoNoYesYesNoNo
Client usageYesNoNoNoNoYesNoNo
MotionsNoNoNoNoYesNoNoNo
ProspectsNoNoNoYesNoNoNoNo
Customer portalNoNoNoNoNoNoNoYes

  • An app permission gives a person an application: Threo, Canopy, Pylon, Builder, and Hub for a customer with a Hub account.
  • A role decides what they can do inside it.

Every person has Threo. When you add a person, you choose which other applications they get. An application that is not available in the customer’s region is greyed out.

To give someone a role in an application, you need a role in that application yourself whose permissions include everything the new role can do. Owners can give any role in their application except a Hub persona role they do not hold, and the owner role itself can be given by anyone with permissions in that application. See What the owner flag adds.


IssueCauseFix
Sign In As is missing for a Canopy adminThe user holds Tenant Admin (no impersonation)Give them Tenant Admin or Owner if they need to act as individual people
You cannot give someone a Pylon or Hub roleYour own role in that application does not include everything that role can do, or it is a Hub persona role you do not holdAsk an Owner of that application to give it. For a Hub persona role, contact Synthreo support
A Pylon user cannot schedule a workflow or add a webhookThe user holds End UserGive them Builder
A Pylon Builder cannot change a company variable on the Variables pageOnly Account Holder and Pylon Admin can change them thereGive them Pylon Admin, or ask an admin to make the change
A Threo permission has no Edit actionCanopy does not change Threo rolesContact Synthreo support to make someone a Customer Admin
An application is greyed out when adding a userIt is not available in the customer’s regionCheck the customer’s region, or grant a different application

What is the difference between an Owner and an Admin? The owner flag. An Admin administers the same things, but an Owner can give any role in their application, while an Admin can give only the roles their own role covers, plus the owner role. Only someone who holds the owner role in an application can sign in as another of its owners in their own company. Inside Pylon, Account Holder and Pylon Admin have the same access.

Can a person have different roles in different applications? Yes. A person can be an Owner in Canopy, a Builder in Pylon, and a Member in Threo at the same time.

Which role should someone get if they only build and test automations? Builder in Pylon.

What is the difference between Tenant Admin and Tenant Admin (no impersonation)? Only Sign In As. Both administer the tenant and both can use Delegate Login. Tenant Admin (no impersonation) cannot act as a named person, and so cannot give anyone the Tenant Admin role.

How do I change someone’s role? Open the person in Canopy and edit the role on their permission. See Managing Permissions.

Home