Roadmap

Three stages. Badged honestly.

We organize by stage, not by calendar date. We won’t call a capability Live until it runs in production for customers. Lanes that are not yet live stay inert until you consent their scopes.

Stage 1 · Live L1 Role Twin Stage 2 · Rolling out L2 escalations Stage 3 · Later Team Twin · L3
Stage 1 Live

L1 Role Twin — first-line Corporate IT.

High-volume, well-defined desk work through the request surfaces you enable. One Role Twin principal, dual audit, confirmation on every write.

What “L1 live” means

  • Accounts, access, licenses, groups, joiner/mover/leaver
  • Password and access recovery paths
  • Routine mailbox / calendar access changes
  • Own directory principal + dual attribution
  • Per-customer isolation · managed or private inference

Platforms · L1 live

  • Microsoft 365 — Entra / directory admin
  • Google Workspace — Workspace directory admin
  • Azure — first-line identity & access
  • GCP — first-line identity & access

Same Role Twin pattern on each; scopes consented per customer.

Role Twin product shape

One twin for a job function (typically first-line IT). Shared queue coverage for the org — not a clone of a person.

MSP multi-tenant

Fleet onboarding, isolation per client, white-label twin identities (your brand, your name — e.g. Avery).

Identity & Trust spine

Confirmation gates, dual audit, narrow action catalog, container boundary. The foundation every later stage inherits.

Stage 2 Rolling out

L2 — well-defined escalations.

The deterministic half of L2: deeper cloud ops, cost and capacity intelligence, diagnostics. Engineers keep the judgment calls. JIT elevation of the twin’s own identity — no standing power.

Rolling out

Cloud resource ops

Start, stop, restart, redeploy — controlled writes across your cloud estate with time-bound elevation.

Rolling out

Cost & capacity intelligence

Spend summary, trend, forecast, budget status, anomaly scan — same twin and audit spine as L1.

Rolling out

Sign-in & risk triage

Diagnostics, session revoke, MFA recovery paths that sit above pure L1 desk work.

Rolling out

More request surfaces

Broader people and system ingress — chat, email, agent-to-agent, tool protocols — same identity mapping and hardening.

Rolling out

Self-service onboarding

Customer portal path so operators spend less time on scripted setup.

Rolling out

Opt-in feedback capture

De-identified interaction capture inside your boundary — off by default.

Stage 3 Later

Team Twin, L3 co-sign, and the wider identity map.

Designed and on the horizon — not shipped. Design partners welcome. We will not market these as live until they are.

Stage 3

Team Twin

Same identity spine as Role Twin, shaped around how your team works — not only a single shared desk identity. People can hand work off, pause or override a thread, and take an interaction back without shutting the twin off for everyone else. Still its own principal. Still never a login as a human.

Complements Role Twin. Not a personality clone. Not credential sharing.

Stage 3

L3 human co-sign

Twin gathers diagnostics, drafts the change, assembles the runbook — then a verified human co-signature before high-risk execution. Requester and approver both on the audit trail. Natural fit with Team Twin handoff.

Stage 3

Okta · JumpCloud adapters

Same twin pattern on more IDMs as adapters land.

Stage 3

Open identity primitives

Publish twin provisioning, capability descriptors, and audit-shape artifacts when stable. About →

At a glance

Stage map.

Stage 1 · Live

L1 Role Twin

M365 · Workspace · Azure · GCP · dual audit · confirmation · private inference option

Stage 2 · Rolling out

L2 Role Twin depth

JIT cloud ops · cost intelligence · diagnostics · more request surfaces · easier onboarding

Stage 3 · Later

Team Twin + L3

Team-shaped bonding · human co-sign · more IDMs · open primitives

Start at Stage 1. Shape Stage 3 with us.

Role Twin L1 is live. Team Twin design partners welcome for the later stage.