Co-Browse
Co-Browse
What is Co-Browse?
Velaro Co-Browse lets an agent see exactly what a visitor sees on the visitor's own screen, live, from inside an active conversation. It's built into the same chat widget the visitor already has loaded — there's no download, no browser extension, and no separate app for either side.
Co-Browse is view-only by design. The agent's viewer is a real-time replica of the visitor's page; the agent cannot click, type, or otherwise control anything on the visitor's page. There is no remote-control or write-back channel. Under the hood, the visitor's browser records DOM events with rrweb and streams them over SignalR; the agent's browser replays those events.
Precision note: the widget the visitor already has loaded does not include the rrweb recording library up front — it loads that automatically from Velaro's own CDN the moment a co-browse session actually starts (ensureRrwebInParent in ParentMessengerProvider.tsx). Don't tell a customer "nothing new ever loads" — the accurate claim is: nothing for them to install, configure, or deploy; Velaro's own code handles it transparently when needed.
Two plans, priced per agent seat
Co-Browse is sold as a per-agent-seat add-on on Starter and above — not a flat per-site fee. Enterprise plans include it free, plan-wide, for every agent (seeded via FeaturePackageInclusion with IsIncluded=1, not the add-on path) — don't tell an Enterprise customer they need to buy seats.
| Co-Browse Pro | Co-Browse Plus | |
|---|---|---|
| Price | $29/agent seat/mo | $49/agent seat/mo |
| Live DOM streaming, no installs | ✅ | ✅ |
Privacy masking (sensitive / no-record / ignore-record classes) |
✅ | ✅ |
| Pattern-based redaction: card numbers, SSNs | ✅ | ✅ |
| Enhanced redaction: email addresses, phone numbers | — | ✅ |
| Assigned-agent-only access | ✅ | ✅ |
| Conversation audit trail | ✅ | ✅ |
Plus is the same product as Pro with a wider redaction net. It's the right recommendation whenever agents will routinely see a visitor's email address or phone number on screen. Don't pitch Plus as a healthcare/compliance feature — it does not detect or redact health data, names, or addresses, only email addresses and phone numbers on top of Pro's card/SSN patterns.
Important scope note: enhanced redaction is a site-wide subscription flag (Subscription.EnableEnhancedPiiRedaction, resolved in CobrowseService), not a per-agent-seat toggle. Once an account is on Co-Browse Plus, every co-browse session on that site gets enhanced redaction — it isn't something you turn on for one agent and not another the way seat assignment works for who can start a session at all.
Seats, not sites
This is licensed per agent, the way a customer would expect to buy it: purchase a number of seats, then either assign specific agents to those seats or auto-assign the whole roster.
- An account buys N seats of a tier (Pro or Plus). Enabling one tier's bundle doesn't automatically remove the other if both were ever enabled — if a customer is switching tiers, confirm the old tier's bundle is disabled, don't assume the system prevents both being active.
- Seats can be assigned to specific named agents, or the account can flip on "auto-assign all agents," which grants every current and future agent a seat automatically.
- An agent without an assigned seat gets a clear refusal if they try to start a session — this is enforced on Velaro's servers, not just hidden in the agent UI, so there's no way to bypass it from the client.
- Removing a seat from an agent (or disabling the add-on) unassigns them immediately; it doesn't require a plan-wide change.
If a customer asks "can I buy 5 seats for my whole team but only license Co-Browse to 2 senior agents," the answer is yes — that's exactly the intended purchase pattern. Note the account is still billed for all 5 seats purchased; unassigned seats aren't free, they're just unused.
Redaction: how it's different from Compliance & Redaction
Don't conflate this with the separate Compliance & Redaction suite (see compliance-redaction-guide.md), which redacts PII in stored chat/email/SMS/ticket transcripts server-side. Co-Browse's redaction is a different, narrower mechanism:
- It runs inside the visitor's own browser, before any DOM event is sent — a masked field or redacted value is never transmitted in the clear, let alone stored.
- It only applies to the live co-browse stream, not to transcripts, tickets, or any other channel.
- Pro redacts card numbers and SSNs by pattern match. Plus adds email addresses and phone numbers to that same client-side pass.
- This is layered on top of, not a replacement for, the
sensitive/no-record/ignore-recordmasking classes a site owner adds to their own page — those still take priority and hide content entirely regardless of tier.
Security summary (for a customer or prospect asking "is this safe?")
- No install for the visitor or the agent. Same chat widget bundle already on the site.
- View-only. No remote control, no ability for an agent to act on the visitor's page.
- Consent-gated. Nothing streams until the visitor clicks Allow; the visitor can stop sharing anytime from their own widget.
- Assignment-enforced. Only the agent assigned to that conversation — and, with seat licensing, only an agent with an assigned Co-Browse seat — can open a session. Checked server-side.
- Masked/redacted at the source. Masking and redaction happen in the visitor's browser before data leaves it.
- Fully audited. Every request/accept/decline/stop event is logged as a system message in the conversation transcript.
Public page
Full customer-facing marketing detail: https://v20.velaro.com/cobrowse (source: velaro-marketing/cobrowse.html).
Was this article helpful?