A Role Twin is a per-customer isolated container bound to a real user identity in your IDM. It accepts work through the surfaces Corporate IT already uses — chat and DMs are common; email, agent-to-agent, and tool-to-tool paths fit the same spine — runs admin actions as itself, and lands every entry in your own audit log under its name, on behalf of a named human. Never a login as them. L1 is live on Microsoft 365, Google Workspace, Azure, and GCP.
Doug needs to grant a new hire an E3 license. He doesn’t open an admin portal. He reaches Avery the way he’d reach any colleague — here, a chat DM. The same confirmation and dual-audit loop applies when the request arrives another way.
avery@yourco.com in the directory and starts a request.The same identity spine covers L1 across your platforms today. L2 paths — deeper cloud ops and cost intelligence — are rolling out under the same gate and audit spine, whatever surface brought the request in.
Accounts, access, licenses, groups, and routine admin — same Role Twin, same confirmation, same dual audit.
L1 live
Entra directory, licenses, groups, mailbox and calendar admin — same twin model.
L1 live
Workspace directory and first-line identity admin under the same twin model.
L1 live
First-line Azure identity and access work for Corporate IT, dual-attributed.
L1 live
First-line Google Cloud identity and access work — same spine as the rest.
The twin’s value is identity, confirmation, and dual audit — not a single front door. Chat is a natural surface for people; the product spine is built so work can also arrive from email, agent-to-agent calls, MCP and other tool protocols, or whatever channel you enable later.
Chat / DM and email-style request paths — where end users already ask IT for help.
Agent-to-agent and tool-to-tool (including MCP) so automation can invoke the same governed twin principal.
Same dual attribution, confirmation policy, and action catalog — the ingress adapter changes, the audit story does not.
# Confirmed run, conceptually on request(from=doug, surface=…): intent = orchestrator.reason(payload) if intent.is_state_changing: reply("I'll {{summary}}. Confirm with 'yes'.") await requester_confirm() result = tools.call(intent.action, intent.args) reply("Done — logged {{result.audit_id}}") # Audit (extract): # Actor: avery@yourco.com # RequestedBy: doug@yourco.com # ConfirmedAt: 2026-05-21T10:14:05Z # Operation: license.assign
Deeper cloud operations and high-stakes writes elevate the twin’s own identity just-in-time, time-bound, then drop. Zero standing infrastructure admin. Same confirmation gate as L1.
Available now
One twin for a job function — usually first-line IT. Shared desk coverage for the org. L1 live across M365, Workspace, Azure, and GCP; L2 for that role is rolling out.
Roadmap
Same spine, shaped around how your team works — handoff, pause, take-back per person without shutting coverage off for everyone. Complements Role Twin. See roadmap →
If it isn’t a registered action, it can’t happen.
20-minute live demo — request work from a Role Twin, watch dual audit, stand up yours when ready.