Subtwin gives Corporate IT a Role Twin — a governed coworker for a job function (typically first-line support) that handles well-defined work wherever requests already reach IT. From a single license grant to a production infrastructure runbook: confirmed, co-signed when needed, audited.
It is a real principal in your directory — its own name, presence, and audit trail — acting on behalf of named people, never a login as them. Every action is dual-attributed and pausable.
What Avery handles in one thread
Same Role Twin, same dual audit, same confirmation spine. On the left: a single desk action. On the right: a production infrastructure incident that used to pull cloud ops, on-call, and a senior approver — the twin diagnoses, drafts the change, waits for human co-sign, then JIT-executes under its own principal.
What a person used to open the admin portal for. One intent, one confirm, one audit row.
What used to need cloud ops, on-call, and a senior approver. Avery gathers evidence, drafts the change, waits for co-sign, then JIT-elevates its own identity to execute.
The twin does the legwork — health, deps, draft change, JIT elevation — but high-risk prod writes wait for a verified human co-signature. Autonomy with a kill switch built in.
“Cost up 40% overnight” — anomaly breakdown, idle pool candidates, stop with confirm. “Failover the secondary region cache” — read topology, draft steps, co-sign, execute.
Own principal, dual attribution, confirmation, narrow action catalog, zero standing infra admin. Complexity is orchestration depth — not a login as a human.
L1 live First-line Corporate IT work across the platforms you already run
L1 is the high-volume, well-defined desk work — accounts, access, licenses, groups, and routine admin — live on Microsoft 365, Google Workspace, Azure, and GCP. L2 (deterministic escalations, deeper cloud ops, specialist paths) is rolling out under the same confirmation gate and audit spine.
Same identity spine and dual audit. Different bonding model. Both are twins of Corporate IT capacity — never a login as a person.
Available now · L1 live
One twin for a role of work — usually first-line IT support. Provisioned as its own directory user (e.g. Avery). Authorized people (and systems) can request work through the surfaces you enable; it covers that role’s queue across Microsoft 365, Google Workspace, Azure, and GCP for L1. Confirms changes, runs as itself, dual-attributes every action to the human requester.
Roadmap
Same spine, shaped around how your team works — so coverage is not only “one desk identity.” People on the team can hand work off, pause or override a thread, and take an interaction back without turning the twin off for everyone else. Still its own principal. Still never a login as a human. Built for denser specialist coverage as L2/L3 mature.
The twin is not a bot identity and not a person. It is a first-class directory principal that acts under its own name, for a named human, with confirmation on the audit trail.
Never signs in as your engineer. Never borrows credentials. Acts under its own delegated identity so “it covered my queue” never means “something logged in as me.”
A real principal in the directory. Actions land in your normal audit log under its own name — the shape compliance already knows how to read.
Any single interaction can be paused, overridden, or handed back to a human without shutting the twin off for the rest of the day.
What changes by tier is how much judgment stays with the human. Audit, confirmation, and “own identity” stay constant.
Live
Password and access recovery, license grants, group changes, joiner/mover/leaver, and routine admin across Microsoft 365, Google Workspace, Azure, and GCP. Role Twin takes the request, confirms the exact action, runs it as itself, logs under its own name.
Rolling out
The deterministic half of escalations: deeper cloud operations, cost and capacity reads, sign-in diagnostics, MFA and risky-user triage. Writes via just-in-time elevation of the twin’s own identity — no standing power. Same platforms, higher judgment threshold.
Roadmap · human-in-the-loop
Diagnostics, draft change, runbook assembly — then a verified human co-signature before anything high-risk runs. Both requester and approver on the audit trail. Pairs naturally with Team Twin handoff.
Helps the IT pro who already knows the console. Rarely helps the person or system that simply needs the change done — and rarely lands clean dual audit.
Great at routing. Still leave a human to open the admin console and push the buttons.
Credential sharing and “act as me” break compliance. Subtwin never uses your people’s credentials.
Webhooks, identity isolation, and audit are a multi-month project before you ship a single license grant.
A licensed user in your IDM. Talks like a coworker, acts like an admin. Every action under its name, on behalf of a named requester. Per-tenant isolated. Private inference available when residency or regulated workloads require it. L1 live across Microsoft 365, Google Workspace, Azure, and GCP.
Each twin is bound to a real principal (e.g. avery@yourco.com) with presence where work is coordinated. Not an employee. Not an opaque bot. A peer in the directory.
Actions go through your cloud APIs as the twin. Entries land where compliance already looks — under the twin’s name, with requester and confirmation bound in.
One isolated container per customer. Separate encrypted token caches, audit logs, and config. A breach of one deployment exposes one customer’s tokens — nothing else.
Choose where reasoning runs. Managed path for most teams; private, isolated inference inside your boundary for residency, regulated workloads, or policy that requires it. Same twin, same audit, same controls either way.
“Jordan starts Monday — set them up.” Account, licenses, groups — one confirmed line instead of a portal safari. L1 live
“Restart the hung web app in prod.” JIT elevate the twin’s own identity, confirm, act — L2 path. Rolling out
“Export privileged changes from Q2.” Already in your audit log. Toil down, coverage up, headcount steady.
Your tenant, your audit log, managed or private inference. Role Twin onboarded in ~20 minutes. Priced per tier of work covered.
Want it managed end-to-end? Deployed and supported by a Subtwin Partner under the same audit posture.
One twin per client tenant, white-labelled, free L1 path when licensing runs through us. No revenue share.
Create the twin identity (e.g. Avery), consent the admin scopes for the platforms you use and the request surfaces you enable. Scripts drive the common paths.
Per-customer container, secrets, twin login, request ingress. ~5 minutes on our side.
No client install for people who already reach IT the usual way. Avery is a real user in the directory — a peer, not a bolt-on.
Role Twin clears L1 across your platforms today; L2 is rolling out so your people spend time on work that needs a human. L1 has a free path when licensing runs through us.