In this paper, we explore how the mdo(1) program can be used to easily and
quickly launch a new process with different credentials and how system
administrators can enable credentials transitions initiated by unprivileged
users by leveraging the mac_do(4) kernel module, foregoing the need to install
third-party programs such as sudo(8) or doas(1) in simple role-based
scenarios.