Skip to main content

How Permission Sets Work

How Permissions Work in Canopy

Permissions in Canopy control what users can see and do across the platform. Permissions are managed using permission sets, which are assigned to users.

Permission Sets and Permissions

  • A permission set is a collection of individual permissions.

  • Each permission can be toggled on or off within a permission set.

  • Permission sets are assigned to users.

  • Users inherit access based on the permissions enabled in their assigned permission set.

This allows firm admins to ensure users only have access to the features and data they need.


Editing Permission Sets

  • Default permission sets cannot be edited.

  • To customize permissions:

  1. Create a copy of the default permission set

  2. Edit the copied permission set as needed

  3. Assign the updated permission set to users

  4. Have the user log out and back in for the changes to take effect.

This ensures the original default permission sets remain unchanged.


Where Permissions Are Managed

To manage permissions:

  1. Go to Settings

  2. Select Access and Permissions

  3. Choose a permission set

  4. Toggle individual permissions on or off

Changes to toggled permissions take effect immediately for users assigned to that permission set. However, changes involving permission set reassignments or license assignments require users to log out and back in for the updates to apply.


Enabling Internal/Admin Time Logging

If a team member cannot see the option to log internal or admin (non-billable) time, it is likely due to their permission set restricting time entry to assigned clients only. Here are three ways to resolve this:

Option 1: Assign an Internal/Firm Client

  1. Create or use an internal client profile (e.g., "Firm Admin").

  2. Assign the user to this internal client in addition to their assigned clients.

  3. The user can now log admin time to the internal client without seeing unrelated clients.

Option 2: Make Client Selection Optional for Time Entries

  1. Navigate to Settings → Billing Settings → Time tab.

  2. Uncheck the "Client" field under Required Fields.

  3. This allows staff to log internal time without selecting a client.

Option 3: Use a Custom Permission Set

  1. Go to Settings → Access and Permissions.

  2. Duplicate the default "Staff (Assigned Clients, No Billing)" role to create a custom permission set.

  3. In the Time permissions, enable the ability to record Internal/Non-Billable time.

  4. Assign the custom set to the user and have them log out and back in for changes to apply. Note: System default permission sets cannot be edited directly. Duplicating creates an editable custom version. Alternatively, assigning a "Staff – All Clients, No Billing" role allows internal time logging but exposes the client list. You can restrict editing/deleting permissions via a custom role.

Resolving Missing Time Tab Visibility

If a user cannot see the Time tab in the left navigation, even with similar permissions to others, they likely lack a Time & Billing license. Follow these steps to resolve the issue:

  1. Go to Settings → Account Management → Time & Billing.

  2. Click Manage and assign licenses.

  3. Assign a Time & Billing license to the user.

  4. If all licenses are in use, free one up by deactivating a former team member.

  5. Have the user log out and back in to see the Time tab.

How Permissions Interact

  • Some permissions depend on other permissions being enabled.

  • For example, certain client permissions are only available when broader client access is turned on.

  • Turning one permission off may automatically disable others.

  • This prevents users from accessing features they no longer have permission to use.

  • Permissions may also be limited by a user’s license type.

  • If a user does not have the required license, enabling a permission will have no effect.

  • For example, users without a Time & Billing license will not see the Time tab in the left navigation, even if permissions are correctly assigned.

Did this answer your question?