Roles & Permissions
User roles and permissions in Synthreo - the role catalogs for ThreoBuilder, ThreoAI, Canopy, and Pylon, and how app permissions and roles work together.
A Role defines what a user can do within each Synthreo application. Roles are per-application: a user holds one role in each application they have access to, and the role catalog is different in each. Each application below lists its current roles.
ThreoBuilder Roles
Section titled “ThreoBuilder Roles”ThreoBuilder (the original Builder application) has six roles, listed from most to least access:
| Role | Access Level |
|---|---|
| Account owner | Full control including billing, settings, and account closure |
| Sysadmin | Full access except account closure |
| Admin | Full access except subscription/payment management |
| Full Power User (FPU) | Same as Admin but cannot manage team members |
| FS Restricted Power User (FS RPU) | Same as FPU but no file system management access |
| DCS Only Power User (DCS OPU) | Limited to the Data Connection System (DCS) only |
These roles belong to ThreoBuilder only. Pylon has its own, shorter catalog - see Pylon Roles.
Pylon Roles
Section titled “Pylon Roles”Pylon has four roles:
| Role | Notes |
|---|---|
| Account Holder | The account owner role for Pylon |
| Admin | Full Pylon administration. It absorbed what used to be a separate Sysadmin role |
| Builder | Build and test agents. This is the role that is called Full Power User in ThreoBuilder |
| End User | Read-only end-user access |
ThreoAI Roles
Section titled “ThreoAI Roles”ThreoAI has two roles:
| Role | Notes |
|---|---|
| Member | The role every new ThreoAI account is provisioned with. Members use ThreoAI and manage their own resources; they are not tenant administrators |
| admin | The ThreoAI tenant administrator |
ThreoAI used to seed a single admin role that every user held. That changed: new accounts now get Member, so the ThreoAI role on a user’s permission row is meaningful rather than uniform.
Canopy Roles
Section titled “Canopy Roles”Canopy has three roles:
| Role | Notes |
|---|---|
| Owner | Everything Admin can do, plus closing the account. The owner flag on this role also gates a set of owner-only operations |
| Admin | Full tenant administration, including delegating into a descendant customer and signing in as one of its users |
| Admin (no impersonation) | Full tenant administration, and may act as a descendant tenant, but cannot log in as one of its users |
Admin and Admin (no impersonation) differ by exactly one thing: impersonation. Both can use Delegate Login to work inside a descendant customer’s tenant; only Admin and Owner can use Sign In As to act as a specific user. See Sign In As and Delegate Login in Canopy.
These three are what Canopy offers. There is no screen for editing what a role contains - you choose which role a user holds, from the role dropdown on their permission.
How Roles Work with Permissions
Section titled “How Roles Work with Permissions”Roles and app permissions are separate concepts:
- App permissions control which applications a user can access: ThreoAI, Builder, Canopy, and Pylon
- Roles control what a user can do within each application
A user needs both an app permission and an appropriate role to access features in a given application.
When you add a user, ThreoAI is included for every user and cannot be unchecked. Builder, Canopy, and Pylon are optional checkboxes, and any of them can be unavailable in a customer’s region - the checkbox is disabled and the dialog says so.
Troubleshooting
Section titled “Troubleshooting”| Issue | Cause | Fix |
|---|---|---|
| User has ThreoBuilder access but cannot manage team members | Assigned FPU role instead of Admin | Update the user’s ThreoBuilder role to Admin or higher |
| User can log in to Canopy but cannot make changes | Assigned an insufficient role | Verify the user has Owner or an Admin role in Canopy |
| Sign In As is missing for a Canopy admin | The user holds Admin (no impersonation) | Assign Admin (or Owner) if that user genuinely needs to act as individual users |
| User cannot access DCS in ThreoBuilder | Role is below DCS OPU | Ensure the user has at least DCS OPU assigned |
| You cannot find a Sysadmin or Full Power User role in Pylon | Those roles do not exist in Pylon | Use Admin in place of Sysadmin, and Builder in place of Full Power User |
| An application checkbox is disabled when adding a user | That application is not available in the customer’s region | Check the customer’s region, or grant a different application |
Can a user have different roles in different applications? Yes. Roles are assigned per-application, and each application has its own catalog. A user can be an Account owner in ThreoBuilder, Admin in Canopy, and a Member in ThreoAI at the same time.
How do I change a user’s role? Navigate to the user in Canopy, expand their permissions, and update the role for the relevant application. See Managing Permissions for step-by-step instructions.
What role should I assign to a new user who only needs to build and test agents? In Pylon, that is the Builder role. In legacy ThreoBuilder, it is Full Power User (FPU). Neither one manages team members or billing.
What is the difference between Admin and Admin (no impersonation) in Canopy? Impersonation, and nothing else. Both administer the tenant and both can delegate into a descendant customer; only Admin can sign in as an individual user of that customer.
Why does the role dropdown show different options for different applications? Because role catalogs are per-application. ThreoBuilder’s six roles, Pylon’s four, Canopy’s three, and ThreoAI’s two are separate lists, and a role name that exists in one application may not exist in another.

