A Role Twin shows up differently depending on who it augments. Every state-changing action still waits for an explicit human yes, and every action lands in your own audit log under the twin’s name. L1 is live across Microsoft 365, Google Workspace, Azure, and GCP.
Marcus runs the desk. His Role Twin (Avery) clears repeatable directory work — wherever those requests arrive — so the team spends time on tickets that need judgment.
Account, licenses, groups, shared access — one confirmed conversation instead of a portal safari.
Reset access, revoke sessions, clear MFA methods for lost-device scenarios — with guards on privileged accounts.
Add/remove members, create standard groups, refuse high-risk and role-assignable groups by policy.
Assign and revoke licenses with pool pre-checks so you don’t fail silently on an exhausted pool.
Disable, revoke sessions, strip non-high-risk groups and licenses — dry-run first when you want a preview.
Out-of-office, delegate access, calendar permissions — reversible admin work without hunting the console.
Role Twin handles the button-pushing half of L2. Engineers keep the judgment. JIT elevation of the twin’s own identity.
Start, stop, restart, redeploy controlled resources. Time-bound elevation — no standing infra admin.
Spend summary, trend, forecast, budget status, anomaly scan across your cloud estate.
Read sign-in signals, revoke sessions, support MFA recovery paths under the same confirmation gate.
High-risk, high-context work: the twin gathers diagnostics and drafts the change; a verified human co-signs before execution.
Collect signals, draft steps, surface risk — then wait for co-signature. Both requester and approver on the audit trail.
When Team Twin ships, specialists can take any interaction back without shutting coverage off for the rest of the team. Roadmap →
Actions already sit in your tenant audit log under the twin’s name — ready for quarterly review.
Requester + confirmation timestamp + twin actor. Built for auditors who ask “who said yes?”
Keep reasoning inside your boundary for residency and regulated workloads without changing the identity story.
Role Twin absorbs the portal work so L1 becomes the farm system for L2, not a permanent queue of password resets.
One Role Twin per client tenant, isolated containers, white-label option — fleet economics without revenue share. For MSPs →
Live demo in a sandbox — bring the tickets you hate most.