Skip to content
synthreo.ai

Create a New User

How MSP admins add a user in Synthreo Canopy for their own organization or a customer tenant, and grant ThreoAI, Builder, Canopy and Pylon product access.

Application: Synthreo Canopy (canopy.synthreo.ai)
Role: MSP Administrator


New users are added through User Management in Canopy. As an MSP admin you create two kinds of accounts:

  • MSP users - staff in your own organization. These are added in your own Canopy session, exactly like a parent-tenant user.
  • Customer users - end users who belong to a specific customer tenant. These are added against that child customer, either from the Customers tab or from inside a delegated session for that customer.

The mechanics of adding a user (the Add User form, the welcome email, bulk import) are identical to standard Canopy user creation, so the steps and screenshots live in the canonical guide:

➡️ Adding a New User in Canopy - covers both parent-tenant (your MSP) and child-customer accounts, plus bulk import and resending welcome emails.

The Add new user dialog asks for Email, First Name and Last Name, plus a Customer selector when you administer more than one customer and have not opened the dialog from a specific customer. It then sends the new user an invitation email.


When you add a user, you also choose which Synthreo applications they can reach. There are four product-access options, not three:

Product AccessGrants access toNotes
ThreoAIThe ThreoAI chat interfaceIncluded for every user. The checkbox is ticked and disabled, and reads “ThreoAI (included for all users)”.
BuilderThreoBuilder, the agent-building consoleOptional. Region gated.
CanopyThe Canopy admin consoleOptional. Region gated. Grant this to your MSP staff, and to a customer admin who should manage their own tenant.
PylonPylon, the automation and agent platformOptional. Region gated.

Region gating. Builder, Canopy and Pylon are only selectable if that application is available in the customer’s region. When it is not, the checkbox is disabled and its tooltip reads “X is not available in this customer’s region.” While Canopy is still resolving which applications the customer has, the tooltip reads “Checking availability…” instead.

For how permissions and roles work after the account exists, see Managing Permissions.


You do not pick a role in the Add User dialog. The role is assigned when the account is provisioned, and you change it afterwards:

  • ThreoAI accounts are created as Member, and that cannot be changed here. New ThreoAI users are not administrators. The ThreoAI permission is created automatically and carries no edit action, so there is no role field for it in Canopy - the rows you can edit are Builder, Canopy and Pylon. If a user genuinely needs elevated ThreoAI rights, raise it with Synthreo rather than looking for a control in the permissions table.
  • Canopy has three roles: Owner, Admin, and Admin (no impersonation). Owner is the only one that can close the account. Admin (no impersonation) may delegate into a descendant tenant but may not sign in as one of that tenant’s users - the attempt is refused with “User does not have permission to impersonate”.
  • Canopy has no screen for editing what a role contains. You choose which role a user holds, not which capabilities the role carries.

To change a role, open the user from User Management, find the permission row, and use its edit action. In the Edit Permission dialog only the Role can be changed; application type, region and account are fixed once the permission exists. The Add Permission dialog asks for Application Type, Region, Account and Role.

The ThreoAI permission is created automatically and has no edit or delete actions in the permissions table.


A naming quirk you will see in the permissions table

Section titled “A naming quirk you will see in the permissions table”

The rebrand never reached the database, so the Application column and the Application Type dropdown still show the stored application names:

  • Canopy appears as Tenant management
  • Builder appears as ThreoBuilder
  • ThreoAI and Pylon appear under their current names

This is expected. Do not treat a row that reads Tenant management as a different product from Canopy.


  • ThreoAI accounts belong to a single tenant: a person cannot hold one ThreoAI account in your MSP and another in a customer. For any other application, one sign-in identity can hold permissions in more than one customer, so check whether adding the permission to their existing identity does the job before creating a second account. See Adding a New User.
  • Changes made in a delegated session apply only to that customer’s tenant.
  • Signing in to canopy.synthreo.ai requires an active Canopy permission. A user with only ThreoAI access cannot reach the admin console.
Home