A quick Google didn't yield much for "canary passwords", but it sounds like monitoring for passwords as opposed to user email/details as described in the OP.
Care to shed a bit more light on what you mean here and how to effectively use them?
I think he’s referring to the idea of having fake users in your database whose passwords should never be used to sign in. Someone successfully signing in with one of those accounts indicates that your user account credentials have been compromised.
Yep. It's either fake users, or weak passwords for existing users.