See it live. Talk it through. Fix it together.
Co-browse rides the same masked DOM stream as the recording, so nothing new leaves the device and no screen share is needed. Voice, drawing, and control are separate capabilities the user confirms one at a time.
One request, one answer. Default is no.
| Capability | What the agent asks | What the user sees first | How it is revoked |
|---|---|---|---|
| 1. Co-browse | View your screen live | Modal: agent name and company, can see this page as you see it with sensitive data hidden, cannot hear, click, or type | Stop sharing in the banner, or close the tab |
| 2. Voice call | Start an audio-only call | Modal plus the browser's own microphone prompt; not recorded unless agreed separately | Hang up; mute is always one click |
| 3. Annotations | Draw on your screen | Modal: can highlight and draw pointers, drawings disappear after 10 s, cannot click or type | Esc clears and revokes |
| 4. Remote control | Click and type for you | Strongest wording, 10-minute expiry, user always has priority | Esc, any mouse or keyboard activity, Stop, expiry |
Declining or revoking a higher rung leaves lower rungs intact. Revoking co-browse ends drawing and control, but a voice call keeps going until the user hangs up.
A banner in a closed shadow root shows which capabilities are on, the agent's name, and a stop button per capability. Host CSS cannot hide it.
A tenant can disable rungs or require re-confirmation on navigation. No tenant can pre-accept anything on the user's behalf.
Free to run, works on locked-down networks.
- SDK live module, 25 KB, lazy
- Live fan-out ≤ 800 ms to the agent
- Voice relay audio only, no video
- Agent console live Player + DevTools
Honest about what a browser lets us do.
The agent interacts with the live mirror. Each action becomes a command the SDK dispatches as a synthetic event, with the user's own activity always taking priority.
Synthetic events are not trusted by the browser: file pickers, clipboard, fullscreen, and autofill will not fire. For those the agent gets a Guide fallback that highlights the target and asks the user to click. Typing into password and card fields, and anything under a mask attribute, is blocked by policy.
Every command is recorded in the session with the agent as actor, shown in the replay with a distinct cursor, and written to the audit log.
Why not drive a headless browser with the user's session?
It would require exfiltrating the user's authentication state to our servers. That is a security and compliance non-starter, so it is not offered and not planned.
The story behind every bug.
Free for 1,000 sessions a month. Strict masking, conditional recording, and Signals are all included.
Replay your first session in five minutes.
Free for 1,000 sessions a month, no credit card. Or leave a work email and we will reach out about the private beta for healthcare and support teams.
You're on the list
We'll reach out to about the private beta.
We'll email when Backstory opens.