About

Twins belong in your identity system.

Subtwin builds the identity layer for agentic Corporate IT work. We started with the highest-volume, best-defined surface — directory L1 — and a single conviction: the agent should be a real principal in your IDM, a twin of your capacity and never a login as your people. Everything else flows from that. Role Twin L1 ships today across M365, Workspace, Azure, and GCP; L2 is rolling out; Team Twin is Stage 3 on the roadmap.

Why we exist

Agent identity is the hard problem.

For years the AI conversation was about what models can do. The harder problem is: who is the AI worker, where does it live, who can it act for, and where does its activity land in the audit log? Those are identity questions, not model questions.

We call our answer a twin. A first-class citizen in your enterprise — a peer of your team, not an employee, not a bot. Identity, presence, and an audit trail like any colleague.

The company is named Subtwin — a wink at the JWT sub claim, the subject identity inside every authenticated token. Your twin is a real subject in your IDM.

As an agentic principal, it accepts work under its own authority from people or systems on the surfaces you enable. On a person’s behalf, it acts for a specific human — dual-attributed — while executing as itself. Never their credentials. Never a login as them.

What we’re optimising for

  • Twins are peers in the directory — not employees, not bots.
  • Every action ties to twin + human requester in the customer’s own audit log.
  • Tenant boundary is a container boundary.
  • The brain is interchangeable. The twin identity is not.
  • Primitives twins depend on get published openly.
Identity primitives

What we’re working on, honestly named.

Not RFCs yet. We’ll share artifacts as the work firms up — so the broader ecosystem can adopt the same model.

Twin provisioning

Standard shape for creating a twin identity across Entra, Workspace, Okta, JumpCloud.

In design

Capability descriptors

How a twin declares what it can do so IDMs and audit systems can reason about it — complement to MCP.

In design

Audit shape

Canonical “twin acted on behalf of human” event shape, including confirmation. Assertion-claim contract frozen v1 internally.

Drafting — contract frozen v1

Why now

Agentic Corporate IT needs governed identity.

MCP as tool lingua franca

Any model that speaks MCP can drive the twin’s hands — including ones that don’t exist yet.

Digital coworkers are real

Enterprises want agents that act across people and systems — with audit and kill switches that look like workforce governance.

Multi-cloud Corporate IT

L1 across Microsoft 365, Google Workspace, Azure, and GCP is where Corporate IT work already lives — with L2 depth rolling out on the same spine.

Build with us.

Role Twin pilots and Team Twin design partners — hello@subtwin.com