Skip to content
synthreo.ai

Roles & Permissions

User roles and permissions in Synthreo - the role catalogs for ThreoBuilder, ThreoAI, Canopy, and Pylon, and how app permissions and roles work together.

A Role defines what a user can do within each Synthreo application. Roles are per-application: a user holds one role in each application they have access to, and the role catalog is different in each. Each application below lists its current roles.


ThreoBuilder (the original Builder application) has six roles, listed from most to least access:

RoleAccess Level
Account ownerFull control including billing, settings, and account closure
SysadminFull access except account closure
AdminFull access except subscription/payment management
Full Power User (FPU)Same as Admin but cannot manage team members
FS Restricted Power User (FS RPU)Same as FPU but no file system management access
DCS Only Power User (DCS OPU)Limited to the Data Connection System (DCS) only

These roles belong to ThreoBuilder only. Pylon has its own, shorter catalog - see Pylon Roles.


Pylon has four roles:

RoleNotes
Account HolderThe account owner role for Pylon
AdminFull Pylon administration. It absorbed what used to be a separate Sysadmin role
BuilderBuild and test agents. This is the role that is called Full Power User in ThreoBuilder
End UserRead-only end-user access

ThreoAI has two roles:

RoleNotes
MemberThe role every new ThreoAI account is provisioned with. Members use ThreoAI and manage their own resources; they are not tenant administrators
adminThe ThreoAI tenant administrator

ThreoAI used to seed a single admin role that every user held. That changed: new accounts now get Member, so the ThreoAI role on a user’s permission row is meaningful rather than uniform.


Canopy has three roles:

RoleNotes
OwnerEverything Admin can do, plus closing the account. The owner flag on this role also gates a set of owner-only operations
AdminFull tenant administration, including delegating into a descendant customer and signing in as one of its users
Admin (no impersonation)Full tenant administration, and may act as a descendant tenant, but cannot log in as one of its users

Admin and Admin (no impersonation) differ by exactly one thing: impersonation. Both can use Delegate Login to work inside a descendant customer’s tenant; only Admin and Owner can use Sign In As to act as a specific user. See Sign In As and Delegate Login in Canopy.

These three are what Canopy offers. There is no screen for editing what a role contains - you choose which role a user holds, from the role dropdown on their permission.


Roles and app permissions are separate concepts:

  • App permissions control which applications a user can access: ThreoAI, Builder, Canopy, and Pylon
  • Roles control what a user can do within each application

A user needs both an app permission and an appropriate role to access features in a given application.

When you add a user, ThreoAI is included for every user and cannot be unchecked. Builder, Canopy, and Pylon are optional checkboxes, and any of them can be unavailable in a customer’s region - the checkbox is disabled and the dialog says so.


IssueCauseFix
User has ThreoBuilder access but cannot manage team membersAssigned FPU role instead of AdminUpdate the user’s ThreoBuilder role to Admin or higher
User can log in to Canopy but cannot make changesAssigned an insufficient roleVerify the user has Owner or an Admin role in Canopy
Sign In As is missing for a Canopy adminThe user holds Admin (no impersonation)Assign Admin (or Owner) if that user genuinely needs to act as individual users
User cannot access DCS in ThreoBuilderRole is below DCS OPUEnsure the user has at least DCS OPU assigned
You cannot find a Sysadmin or Full Power User role in PylonThose roles do not exist in PylonUse Admin in place of Sysadmin, and Builder in place of Full Power User
An application checkbox is disabled when adding a userThat application is not available in the customer’s regionCheck the customer’s region, or grant a different application

Can a user have different roles in different applications? Yes. Roles are assigned per-application, and each application has its own catalog. A user can be an Account owner in ThreoBuilder, Admin in Canopy, and a Member in ThreoAI at the same time.

How do I change a user’s role? Navigate to the user in Canopy, expand their permissions, and update the role for the relevant application. See Managing Permissions for step-by-step instructions.

What role should I assign to a new user who only needs to build and test agents? In Pylon, that is the Builder role. In legacy ThreoBuilder, it is Full Power User (FPU). Neither one manages team members or billing.

What is the difference between Admin and Admin (no impersonation) in Canopy? Impersonation, and nothing else. Both administer the tenant and both can delegate into a descendant customer; only Admin can sign in as an individual user of that customer.

Why does the role dropdown show different options for different applications? Because role catalogs are per-application. ThreoBuilder’s six roles, Pylon’s four, Canopy’s three, and ThreoAI’s two are separate lists, and a role name that exists in one application may not exist in another.

Home