Endpoint privilege management for Windows

Admin rights for half an hour.
Not forever.

People get administrator rights on their own device only when they need them. A policy or an approver decides, the rights remove themselves when the time is up, and every program run as admin is on record.

No sign-up. A mock company, reset every hour.

demo.wannabe-admin.com
The Wannabe Admin overview: two admin sessions active, three requests waiting for approval, request outcomes for the last seven days.

How it works

Ask, decide, done. The rights leave on their own.

  1. 1

    Ask

    From the tray icon on their Windows device: for how long, and why.

  2. 2

    Decide

    The policy grants it straight away, refuses it, or sends it to an approver, who decides in the portal with a reason.

  3. 3

    Expire

    The agent removes the rights when the window closes. Every program started as administrator is logged, with its path and who signed it.

The desktop app on a Windows device: request administrator rights for 30 minutes, 1 hour or 2 hours.
What people see on their computer, in your colours.

Features

Least privilege without the ticket queue

Time-bound admin sessions

Local administrator for a fixed window, enforced by the agent on the device and removed automatically.

Rules per application

Match on publisher, path, product or file hash. Approve automatically, ask a person, or block.

Approvals that make sense

Approvers see who, on which device, what and why. Grant, shorten, deny or revoke early.

An audit trail people can read

Append-only and hash-chained, so gaps and edits show. Written as sentences, not raw JSON.

Entra ID and Intune

Sign in with Microsoft, roles from Entra app roles, more than one tenant. The agent ships as a ready Intune package.

Device identity without a PKI

Devices enrol themselves. The server checks Entra, then issues each one a client certificate.

Signed policies

Every policy is signed with Ed25519. An agent refuses any document that does not verify.

Your brand in the tray

Name, colours and logo of the desktop app, set in the portal with a live preview.

Inside the portal

One place for policy, devices and evidence

Roadmap

What's coming

  1. Available

    Windows

    Tray app, shipped as an Intune package.

  2. Available

    Approve by email or Teams

    Approvers hear about a request right away, and can decide from the message.

  3. Available

    Two-step sign-in for admins

    A security key or a code from an authenticator app, after the password.

  4. Planned

    Offline with a one-time code

    A code from the service desk grants admin for a while.

  5. Planned

    macOS

    Same flow from the menu bar, via Intune or any MDM.

  6. Planned

    Malware check

    Defender or VirusTotal verdict before elevation.

  7. Planned

    SIEM export

    Audit trail to Sentinel, Splunk or syslog.

Live demo

Be the admin of a company that does not exist

Brightwater Logistics has 21 devices, 14 people who keep asking for admin rights, and a month of history. New requests arrive while you look around.

  • Approve, deny and revoke requests
  • Change the policy and watch the next request follow it
  • Follow everything in the audit trail
  • Single sign-on, setup and downloads are read-only
Open the demo

Shared with other visitors and reset every hour. Do not type anything personal.