What CANOPY shows
CANOPY, the Coverage map, connects your security tools to the capabilities they support, so you can see coverage, gaps, and overlap.
Last updated September 22, 2026
CANOPY is the Coverage map. It connects your security stack to the work that stack is supposed to do. Tools sit on one side, capabilities on the other, and the lines between them tell you where you are covered and where you are exposed.
CANOPY is interactive. Search any tool and jump straight to it, with a detail panel that floats over the map so the picture never shrinks. Click a tool or an integration link for its details, and hover to highlight what connects to what.
Capabilities are the source of truth in Pytheus. A capability is a discrete security function or process, such as Patch Management or Identity Provisioning. CANOPY shows which of your tools support each capability, which capabilities have no tool behind them, and where several tools claim the same function.
That picture answers three questions security leaders ask constantly:
Which capabilities are covered, and by what
Where you have gaps, meaning a capability with no supporting tool
Where you have overlap, meaning more than one tool doing the same job
A gap on CANOPY is different from a low maturity score. CANOPY tells you whether a capability has tooling behind it. Your CAMP assessment tells you how well that capability is actually performed.
CANOPY does not score your program on its own. It gives the context behind the numbers. When a domain scores poorly in CAMP, CANOPY often explains why: no tool, the wrong tool, or three tools fighting over the same ground.
You build this view from your Technology inventory. Start with Adding tools, then review Tool-to-capability mappings.