We organize by stage, not by calendar date. We won’t call a capability Live until it runs in production for customers. Lanes that are not yet live stay inert until you consent their scopes.
High-volume, well-defined desk work through the request surfaces you enable. One Role Twin principal, dual audit, confirmation on every write.
Same Role Twin pattern on each; scopes consented per customer.
One twin for a job function (typically first-line IT). Shared queue coverage for the org — not a clone of a person.
Fleet onboarding, isolation per client, white-label twin identities (your brand, your name — e.g. Avery).
Confirmation gates, dual audit, narrow action catalog, container boundary. The foundation every later stage inherits.
The deterministic half of L2: deeper cloud ops, cost and capacity intelligence, diagnostics. Engineers keep the judgment calls. JIT elevation of the twin’s own identity — no standing power.
Rolling out
Start, stop, restart, redeploy — controlled writes across your cloud estate with time-bound elevation.
Rolling out
Spend summary, trend, forecast, budget status, anomaly scan — same twin and audit spine as L1.
Rolling out
Diagnostics, session revoke, MFA recovery paths that sit above pure L1 desk work.
Rolling out
Broader people and system ingress — chat, email, agent-to-agent, tool protocols — same identity mapping and hardening.
Rolling out
Customer portal path so operators spend less time on scripted setup.
Rolling out
De-identified interaction capture inside your boundary — off by default.
Designed and on the horizon — not shipped. Design partners welcome. We will not market these as live until they are.
Stage 3
Same identity spine as Role Twin, shaped around how your team works — not only a single shared desk identity. People can hand work off, pause or override a thread, and take an interaction back without shutting the twin off for everyone else. Still its own principal. Still never a login as a human.
Complements Role Twin. Not a personality clone. Not credential sharing.
Stage 3
Twin gathers diagnostics, drafts the change, assembles the runbook — then a verified human co-signature before high-risk execution. Requester and approver both on the audit trail. Natural fit with Team Twin handoff.
Stage 3
Same twin pattern on more IDMs as adapters land.
Stage 3
Publish twin provisioning, capability descriptors, and audit-shape artifacts when stable. About →
Stage 1 · Live
M365 · Workspace · Azure · GCP · dual audit · confirmation · private inference option
Stage 2 · Rolling out
JIT cloud ops · cost intelligence · diagnostics · more request surfaces · easier onboarding
Stage 3 · Later
Team-shaped bonding · human co-sign · more IDMs · open primitives
Role Twin L1 is live. Team Twin design partners welcome for the later stage.