Skip to content
synthreo.ai

Sign In As and Delegate Login in Canopy

Two ways to reach a child customer's apps in Canopy: Delegate Login for Canopy, ThreoBuilder, and Pylon; Sign In As for ThreoAI and Pylon, on the Accounts tab.

There are two ways to reach a child customer’s applications from Canopy. They are not interchangeable, and they leave different traces:

  • Delegate Login puts you in the child tenant, acting as an administrator of that organization.
  • Sign In As puts you in the session as a specific user - impersonation. It is logged, and for ThreoAI it requires that user’s prior consent.

Both start from the same place: Customers, the customer’s row, the Accounts tab.


  • Access to Canopy with an administrator role.
  • The target must be a child customer. You cannot use either flow against your own organization’s users.

  1. Select Customers in the left navigation.
  2. Click the customer’s row. The row itself is the link - there is no menu button and no expand arrow.
  3. Open the Accounts tab.
  4. Pick the app sub-tab you need: Canopy, ThreoAI, ThreoBuilder, or Pylon.

Each sub-tab lists that app’s accounts for the customer, with the count in the heading (for example, “ThreoAI Accounts (14)”).


Delegate Login is how you step into a child customer’s tenant as an administrator. Select Delegate Login on the app sub-tab and confirm the Confirm Delegation dialog.

It is offered on the Canopy, ThreoBuilder, and Pylon sub-tabs. There is no Delegate Login on the ThreoAI sub-tab - ThreoAI is reached with Sign In As instead, because what you almost always need there is one user’s own view.

What happens next depends on the app:

Sub-tabWhat opens
CanopyThis window switches to the delegated tenant. A banner appears at the top; use its Return to <your organization> control to come back.
ThreoBuilder, PylonA new window opens on the delegated session. Canopy confirms with “Delegated login opened in a new window.”
ThreoAINot offered. Use Sign In As.

While delegated, Canopy itself follows the delegated tenant. Screens that are scoped to “your” organization - Platform Admin, Settings, the Dashboard - all show the child customer’s data, because your active customer has changed.


Sign In As is impersonation: the session is minted as that user, not as the tenant. It is offered on the ThreoAI and Pylon sub-tabs.

  1. Open the ThreoAI or Pylon sub-tab.
  2. Select Sign In As next to the user.
  3. Confirm the Impersonate User dialog.

The dialog states plainly: “Your impersonation of this user will be logged.”

Use it on Pylon when you need to work with a specific user’s own connections. Delegating into the tenant gives you the organization’s shared credentials; signing in as the user gives you theirs.

For ThreoAI, Sign In As is gated on consent the user grants themselves. The button is disabled until they do, and hovering it explains the state:

TooltipMeaning
Consent Not GrantedThe user has not granted support access. The button stays disabled.
Expires <date and time>Consent is granted and will lapse at that time.
No ExpirationConsent is granted with no end date.

The user grants it from their ThreoAI account menu (support access). Ask them to turn it on; there is no way to grant it on their behalf from Canopy.

Pylon has no consent gate. Pylon rows show a plain, always-enabled button with no tooltip.


GoalUse
Administer a child tenant (its settings, users, models)Delegate Login, Canopy sub-tab
Open a child tenant’s ThreoBuilder or Pylon as an administratorDelegate Login, ThreoBuilder or Pylon sub-tab
See exactly what one user sees in ThreoAISign In As, ThreoAI sub-tab (needs their consent)
Bind a user’s own connectors while building in PylonSign In As, Pylon sub-tab

  • Delegated into Canopy in place: use Return to <your organization> in the banner.
  • Delegated or impersonating in a new window: close that window. Your original Canopy session is unaffected.

SymptomCauseFix
Sign In As is greyed out on a ThreoAI rowThe user has not granted support-access consentAsk the user to grant it in ThreoAI, then reload the Accounts tab
Sign In As is not offered at all on a rowYou are on the Canopy or ThreoBuilder sub-tab, which do not support itSwitch to the ThreoAI or Pylon sub-tab, or use Delegate Login instead
No new window opened after Delegate LoginYou delegated into Canopy, which switches in placeLook for the delegation banner at the top of the page
No new window opened for ThreoAI, ThreoBuilder, or PylonBrowser pop-up blockerAllow pop-ups for the Canopy site and try again
The delegated session shows fewer features than expectedThe target account lacks that app permissionCheck the user’s permissions on the customer’s Users tab first
You cannot find the userYou opened the wrong tenant, or the user sits at a different level of the hierarchyConfirm which customer you opened before searching again

Can I use these flows inside my own organization? No. Both are for child customers only.

Which flow works for ThreoAI? Sign In As, from the ThreoAI sub-tab of the customer’s Accounts tab, and only once that user has granted consent.

Does the user know I signed in as them? For ThreoAI they granted consent, so they opted in. In every case the confirmation dialog states that your impersonation will be logged. Treat it as an on-the-record action rather than a silent one.

Can I sign in as a user in ThreoBuilder? No. ThreoBuilder offers Delegate Login only. Sign In As is available on ThreoAI and Pylon.

How do I end a delegated Canopy session? Use Return to <your organization> in the banner at the top of the page.