Corporate IT · Role Twin

Clear the IT queue. Keep the humans for judgment.

Subtwin gives Corporate IT a Role Twin — a governed coworker for a job function (typically first-line support) that handles well-defined work wherever requests already reach IT. From a single license grant to a production infrastructure runbook: confirmed, co-signed when needed, audited.

It is a real principal in your directory — its own name, presence, and audit trail — acting on behalf of named people, never a login as them. Every action is dual-attributed and pausable.

Augments staff — doesn't replace them · Dual audit in your own log · Private inference when isolation matters · L1 live · L2 rolling out

What Avery handles in one thread

  • Simple L1 — one action, one confirmation (live today)
  • Complex L3 infra — diagnose, draft runbook, human co-sign, JIT execute — work that used to need a whole squad

See side-by-side →

What it looks like

One request. Or a whole runbook.

Same Role Twin, same dual audit, same confirmation spine. On the left: a single desk action. On the right: a production infrastructure incident that used to pull cloud ops, on-call, and a senior approver — the twin diagnoses, drafts the change, waits for human co-sign, then JIT-executes under its own principal.

L1 · live

Simple — one action

What a person used to open the admin portal for. One intent, one confirm, one audit row.

L2 · diagnose & ops L3 · human co-sign

Complex — production infrastructure

What used to need cloud ops, on-call, and a senior approver. Avery gathers evidence, drafts the change, waits for co-sign, then JIT-elevates its own identity to execute.

Why infra L3 is different

The twin does the legwork — health, deps, draft change, JIT elevation — but high-risk prod writes wait for a verified human co-signature. Autonomy with a kill switch built in.

Other complex infra examples

“Cost up 40% overnight” — anomaly breakdown, idle pool candidates, stop with confirm. “Failover the secondary region cache” — read topology, draft steps, co-sign, execute.

Same spine as L1

Own principal, dual attribution, confirmation, narrow action catalog, zero standing infra admin. Complexity is orchestration depth — not a login as a human.

L1 live First-line Corporate IT work across the platforms you already run

Microsoft 365 · L1 live
Google Workspace · L1 live
Azure · L1 live
GCP · L1 live
L2 escalations · rolling out
Okta · roadmap
JumpCloud · roadmap

L1 is the high-volume, well-defined desk work — accounts, access, licenses, groups, and routine admin — live on Microsoft 365, Google Workspace, Azure, and GCP. L2 (deterministic escalations, deeper cloud ops, specialist paths) is rolling out under the same confirmation gate and audit spine.

Product shapes

Role Twin for a job function. Team Twin for how your people work.

Same identity spine and dual audit. Different bonding model. Both are twins of Corporate IT capacity — never a login as a person.

Available now · L1 live

Role Twin

One twin for a role of work — usually first-line IT support. Provisioned as its own directory user (e.g. Avery). Authorized people (and systems) can request work through the surfaces you enable; it covers that role’s queue across Microsoft 365, Google Workspace, Azure, and GCP for L1. Confirms changes, runs as itself, dual-attributes every action to the human requester.

  • Own principal — not a shared service account
  • On behalf of requesters, never as them
  • Best for shared desk / function coverage
  • L2 for that role is rolling out on the same twin

Roadmap

Team Twin

Same spine, shaped around how your team works — so coverage is not only “one desk identity.” People on the team can hand work off, pause or override a thread, and take an interaction back without turning the twin off for everyone else. Still its own principal. Still never a login as a human. Built for denser specialist coverage as L2/L3 mature.

  • Team-shaped coverage, not a personality clone
  • Per-interaction handoff to a named human
  • Complements Role Twin; does not replace the desk model
  • Design partners welcome — see Roadmap

Team Twin on the roadmap →

Identity model

Independent principal. Dual attribution.

The twin is not a bot identity and not a person. It is a first-class directory principal that acts under its own name, for a named human, with confirmation on the audit trail.

Requester doug@yourco.com
Role Twin avery@yourco.com
Your audit log Twin + human + confirm time

Of you, not as you

Never signs in as your engineer. Never borrows credentials. Acts under its own delegated identity so “it covered my queue” never means “something logged in as me.”

Not a shadow bot

A real principal in the directory. Actions land in your normal audit log under its own name — the shape compliance already knows how to read.

Pausable, overridable

Any single interaction can be paused, overridden, or handed back to a human without shutting the twin off for the rest of the day.

Identity & Trust deep dive →
L1 → L2 → L3

One spine. Honest badges per stage.

What changes by tier is how much judgment stays with the human. Audit, confirmation, and “own identity” stay constant.

Live

L1 — the routine, cleared

Password and access recovery, license grants, group changes, joiner/mover/leaver, and routine admin across Microsoft 365, Google Workspace, Azure, and GCP. Role Twin takes the request, confirms the exact action, runs it as itself, logs under its own name.

Rolling out

L2 — well-defined escalations

The deterministic half of escalations: deeper cloud operations, cost and capacity reads, sign-in diagnostics, MFA and risky-user triage. Writes via just-in-time elevation of the twin’s own identity — no standing power. Same platforms, higher judgment threshold.

Roadmap · human-in-the-loop

L3 — twin prepares, human decides

Diagnostics, draft change, runbook assembly — then a verified human co-signature before anything high-risk runs. Both requester and approver on the audit trail. Pairs naturally with Team Twin handoff.

What Subtwin is not

Corporate IT needs more than another portal or plugin.

Generic tools bolted onto admin power

Helps the IT pro who already knows the console. Rarely helps the person or system that simply needs the change done — and rarely lands clean dual audit.

Ticket routers that never take action

Great at routing. Still leave a human to open the admin console and push the buttons.

Personal AI using a human’s login

Credential sharing and “act as me” break compliance. Subtwin never uses your people’s credentials.

Build-it-yourself platform automation

Webhooks, identity isolation, and audit are a multi-month project before you ship a single license grant.

Avery — Role Twin, real principal, dual audit

A licensed user in your IDM. Talks like a coworker, acts like an admin. Every action under its name, on behalf of a named requester. Per-tenant isolated. Private inference available when residency or regulated workloads require it. L1 live across Microsoft 365, Google Workspace, Azure, and GCP.

Why Subtwin

Four design choices everything else flows from.

A real user, not a service account

Each twin is bound to a real principal (e.g. avery@yourco.com) with presence where work is coordinated. Not an employee. Not an opaque bot. A peer in the directory.

Audit in your own log

Actions go through your cloud APIs as the twin. Entries land where compliance already looks — under the twin’s name, with requester and confirmation bound in.

Hard boundary per customer

One isolated container per customer. Separate encrypted token caches, audit logs, and config. A breach of one deployment exposes one customer’s tokens — nothing else.

Private inference when isolation matters

Choose where reasoning runs. Managed path for most teams; private, isolated inference inside your boundary for residency, regulated workloads, or policy that requires it. Same twin, same audit, same controls either way.

In practice

What Corporate IT hands off.

Service desk

“Jordan starts Monday — set them up.” Account, licenses, groups — one confirmed line instead of a portal safari. L1 live

Cloud ops

“Restart the hung web app in prod.” JIT elevate the twin’s own identity, confirm, act — L2 path. Rolling out

Security & leadership

“Export privileged changes from Q2.” Already in your audit log. Toil down, coverage up, headcount steady.

Use cases by role →
Built for Corporate IT

Augment your team. Don’t backfill it.

Corporate IT — direct

Your tenant, your audit log, managed or private inference. Role Twin onboarded in ~20 minutes. Priced per tier of work covered.

Talk to us →

Verified partner delivery

Want it managed end-to-end? Deployed and supported by a Subtwin Partner under the same audit posture.

Partner program →

MSPs — fleet of Role Twins

One twin per client tenant, white-labelled, free L1 path when licensing runs through us. No revenue share.

For MSPs →

Operator view

Onboard a Role Twin in under 20 minutes.

Your identity admin provisions the twin

Create the twin identity (e.g. Avery), consent the admin scopes for the platforms you use and the request surfaces you enable. Scripts drive the common paths.

We run onboard-customer

Per-customer container, secrets, twin login, request ingress. ~5 minutes on our side.

Requests start flowing

No client install for people who already reach IT the usual way. Avery is a real user in the directory — a peer, not a bolt-on.

Move Corporate IT up a tier.

Role Twin clears L1 across your platforms today; L2 is rolling out so your people spend time on work that needs a human. L1 has a free path when licensing runs through us.