Roles & Permissions
Synthreo roles reference - what each Owner, Admin, Builder, and End User role lets a person do in Canopy, Pylon, Threo, and Hub, and how the roles differ.
A role decides what a person can do inside one application. Everyone holds one role in each application they can use. To grant an application and choose the role, see Managing Permissions.
The four levels
Section titled “The four levels”Every application’s roles fit the same four levels:
| Level | Who it is for |
|---|---|
| Owner | The person a customer account is created for. Has everything an Admin has, plus the owner flag (below) |
| Admin | People who run the account: they manage users, settings, and everything shared across the company |
| Builder | The people doing the work. They build and run their own work and use what is shared with them, with no account-wide settings |
| End User | The most limited role in an application |
Each application’s role names for those levels:
| Level | Canopy | Pylon | Threo | Hub |
|---|---|---|---|---|
| Owner | Owner | Account Holder | Customer Admin | Account Holder |
| Admin | Tenant Admin, Tenant Admin (no impersonation) | Pylon Admin | - | - |
| Builder | - | Builder | - | - |
| End User | - | End User | Member | Member |
What the owner flag adds
Section titled “What the owner flag adds”An Owner role carries an owner flag. An Admin administers the same things an Owner does, with two differences:
- Giving roles. You can give someone a role only if your own role in that application includes everything the new role can do. An Owner can give any role in their application, except a Hub persona role they do not hold themselves (see Hub Roles).
- Signing in as an owner. To use Sign In As on an owner in your own company, you must hold the owner role in that same application yourself.
The owner role itself is the exception to the first rule: anyone who holds a role with permissions in that application can give it, and more than one person can hold it.
Canopy Roles
Section titled “Canopy Roles”Canopy has three roles. All three administer your organization and the customers under it: people, customers, company details, billing details, and branding.
| Role | What it covers |
|---|---|
| Owner | Full administration, plus the owner flag |
| Tenant Admin | Full administration, including Delegate Login and Sign In As |
| Tenant Admin (no impersonation) | Full administration and Delegate Login, without Sign In As |
Delegate Login lets you work inside a customer below yours. Sign In As lets you act as one named person there, and signing in as a Threo user also needs that person’s consent. See Sign In As and Delegate Login in Canopy.
| Permission | Owner | Tenant Admin | Tenant Admin (no impersonation) |
|---|---|---|---|
| Add, edit, and remove people | Yes | Yes | Yes |
| Create, manage, and delete customers below yours | Yes | Yes | Yes |
| Edit company details, billing details, and branding | Yes | Yes | Yes |
| Work inside a customer below yours (Delegate Login) | Yes | Yes | Yes |
| Act as a named person there (Sign In As) | Yes | Yes | No |
| Give someone the Owner role | Yes | Yes | Yes |
| Give someone the Tenant Admin role | Yes | Yes | No |
In your own company, nobody can Sign In As someone in Canopy itself. Signing in as an owner of another application depends on your role in that application, not your Canopy role (see What the owner flag adds).
Nobody can delete their own company or remove themselves.
Pylon Roles
Section titled “Pylon Roles”| Role | Level | What it covers |
|---|---|---|
| Account Holder | Owner | Everything Pylon Admin has, plus the owner flag |
| Pylon Admin | Admin | Runs the account: sees every automation, makes automations company-wide and shares them, chooses who they run as, and manages connectors, skills, variables, templates, and Teams settings for the whole company |
| Builder | Builder | Builds, tests, publishes, and schedules their own automations, and uses anything shared with them |
| End User | End User | Builds and runs their own automations and uses what is shared with them, but cannot schedule workflows, add webhooks to them, or use company variables or shared agent memory |
Inside Pylon, Account Holder and Pylon Admin have the same access. They differ only by the owner flag.
| Permission | Account Holder | Pylon Admin | Builder | End User |
|---|---|---|---|---|
| Build and edit their own agents and workflows | Yes | Yes | Yes | Yes |
| See and edit every automation in the account | Yes | Yes | No | No |
| Schedule a workflow or give it a webhook | Yes | Yes | Yes | No |
| Use shared company variables | Yes | Yes | Yes | No |
| Change shared company variables on the Variables page | Yes | Yes | No | No |
| Change shared company variables from inside an automation | Yes | Yes | Yes | No |
| Manage shared agent memory | Yes | Yes | Yes | No |
| Install a connector for the whole company | Yes | Yes | No | No |
| Add a skill for the whole company | Yes | Yes | No | No |
| Make an automation company-wide and share it | Yes | Yes | No | No |
| Choose who an automation runs as | Yes | Yes | No | No |
| Publish and deploy templates | Yes | Yes | No | No |
| Change the company’s Teams notification settings | Yes | Yes | No | No |
Threo Roles
Section titled “Threo Roles”| Role | Level | What it covers |
|---|---|---|
| Customer Admin | Owner | Manages Threo for the whole company: company connectors, company skills, and other people’s activity |
| Member | End User | Uses Threo with their own connectors, skills, and Experts |
The person a customer is created for is its Customer Admin. Everyone added after that is a Member. Canopy has no Edit action on a Threo permission; to make someone a Customer Admin, contact Synthreo support.
| Permission | Customer Admin | Member |
|---|---|---|
| Connect their own connectors | Yes | Yes |
| Install a connector for the whole company | Yes | No |
| Choose which connector tools the whole company may use | Yes | No |
| Add their own skills | Yes | Yes |
| Add and manage skills for the whole company | Yes | No |
| Manage other people’s skills and shortcuts | Yes | No |
| See other people’s profiles and activity, including in customers below yours | Yes | No |
Hub Roles
Section titled “Hub Roles”You give someone a Hub role in Canopy with Add Permission on their user, choosing Hub as the Application Type. Hub is listed there only when the customer has a Hub account. See Managing Permissions.
| Role | Level | What it covers |
|---|---|---|
| Account Holder | Owner | Administers the organization’s Hub. On a partner (MSP or reseller) organization, it opens the partner portal |
| Member | End User | Learner access: Academy, documentation, and notifications |
Synthreo also sets up five persona roles where they fit. Each fits one kind of organization, and the Role list only offers a persona that fits the customer:
| Role | Fits | What it covers |
|---|---|---|
| Sales | Synthreo | CRM, customers, prospects, Academy, files, documentation, and feedback |
| Professional Services | Synthreo | Delivery (projects, tickets, and time), motions, customers, files, documentation, feedback, and setting up new customers |
| Partner Portal | Partner (MSP or reseller) organizations | Channel CRM, delivery for its own customers, customers, client usage, Academy, files, documentation, and feedback |
| Partner Technician | Partner (MSP or reseller) organizations | Learner access: Academy, notifications, and documentation |
| End Customer | Every other organization | The customer portal, Academy, documentation, and notifications |
A persona role’s access comes from its name. To give someone a persona, you must hold that persona yourself, unless you are Synthreo.
An Account Holder on a partner organization gets the same access as Partner Portal, plus Billing and setting up new customers. A Member gets the same access as Partner Technician.
The table shows what each role sees in the Hub menu.
| Permission | Account Holder (partner organization) | Account Holder (any other organization) | Member | Sales | Professional Services | Partner Portal | Partner Technician | End Customer |
|---|---|---|---|---|---|---|---|---|
| Documentation | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Notifications | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Academy | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes |
| Billing | Yes | Yes | No | No | No | No | No | No |
| Feedback | Yes | Yes | No | Yes | Yes | Yes | No | No |
| Set up new customers | Yes | Yes | No | No | Yes | No | No | No |
| Customer list | Yes | No | No | Yes | Yes | Yes | No | No |
| Files | Yes | No | No | Yes | Yes | Yes | No | No |
| CRM | Yes | No | No | Yes | No | Yes | No | No |
| Delivery | Yes | No | No | No | Yes | Yes | No | No |
| Client usage | Yes | No | No | No | No | Yes | No | No |
| Motions | No | No | No | No | Yes | No | No | No |
| Prospects | No | No | No | Yes | No | No | No | No |
| Customer portal | No | No | No | No | No | No | No | Yes |
How Roles Work with Permissions
Section titled “How Roles Work with Permissions”- An app permission gives a person an application: Threo, Canopy, Pylon, Builder, and Hub for a customer with a Hub account.
- A role decides what they can do inside it.
Every person has Threo. When you add a person, you choose which other applications they get. An application that is not available in the customer’s region is greyed out.
To give someone a role in an application, you need a role in that application yourself whose permissions include everything the new role can do. Owners can give any role in their application except a Hub persona role they do not hold, and the owner role itself can be given by anyone with permissions in that application. See What the owner flag adds.
Troubleshooting
Section titled “Troubleshooting”| Issue | Cause | Fix |
|---|---|---|
| Sign In As is missing for a Canopy admin | The user holds Tenant Admin (no impersonation) | Give them Tenant Admin or Owner if they need to act as individual people |
| You cannot give someone a Pylon or Hub role | Your own role in that application does not include everything that role can do, or it is a Hub persona role you do not hold | Ask an Owner of that application to give it. For a Hub persona role, contact Synthreo support |
| A Pylon user cannot schedule a workflow or add a webhook | The user holds End User | Give them Builder |
| A Pylon Builder cannot change a company variable on the Variables page | Only Account Holder and Pylon Admin can change them there | Give them Pylon Admin, or ask an admin to make the change |
| A Threo permission has no Edit action | Canopy does not change Threo roles | Contact Synthreo support to make someone a Customer Admin |
| An application is greyed out when adding a user | It is not available in the customer’s region | Check the customer’s region, or grant a different application |
What is the difference between an Owner and an Admin? The owner flag. An Admin administers the same things, but an Owner can give any role in their application, while an Admin can give only the roles their own role covers, plus the owner role. Only someone who holds the owner role in an application can sign in as another of its owners in their own company. Inside Pylon, Account Holder and Pylon Admin have the same access.
Can a person have different roles in different applications? Yes. A person can be an Owner in Canopy, a Builder in Pylon, and a Member in Threo at the same time.
Which role should someone get if they only build and test automations? Builder in Pylon.
What is the difference between Tenant Admin and Tenant Admin (no impersonation)? Only Sign In As. Both administer the tenant and both can use Delegate Login. Tenant Admin (no impersonation) cannot act as a named person, and so cannot give anyone the Tenant Admin role.
How do I change someone’s role? Open the person in Canopy and edit the role on their permission. See Managing Permissions.

