Live Assist
Live Assist lets a support agent watch a session as it happens and, with the user’s permission, talk to them, draw on the page, or click and type for them.
Watching needs no prompt. The agent’s view is rendered from the same masked stream the session recording already stores. One Support access request grants chat, drawing, and remote control; voice is the only separate request.
Enabling
Section titled “Enabling”Live Assist is on by default and needs no configuration. The live module is only downloaded once an agent is actually watching, and nothing is ever shown to the user unless they are asked for something.
Backstory.init({ projectKey: "pk_live_…", live: { remoteControl: "consent-per-session" }, // or "off" to refuse control outright});Backstory.live.showCode(); // optional: a 6-digit code the user can read to an agentTo turn it off, set live: { enabled: false } in the snippet, or turn it off for the whole project without a redeploy:
curl -X PATCH "$API/v1/projects/$PROJECT_ID/recording" \ -H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \ -d '{"flags":{"live":false}}'The flag rides the SDK’s remote config, so pages pick it up on their next config refresh. Narrower switches also exist: liveDisable:control, liveDisable:voice, and so on auto-decline a single capability.
The live module is lazy-loaded (~25 KB) only when an agent is waiting or showCode() is called.
The consent ladder
Section titled “The consent ladder”| Capability | Agent asks | User sees | Revoke |
|---|---|---|---|
| Support access | Chat, draw, highlight, click, and type | One clear prompt for the bundled support tools; sensitive data stays masked | Esc; Stop support; either side ends the assist |
| Voice | Start an audio-only call | A separate audio-only request and browser microphone prompt | Hang up |
| Rules: viewing the masked live session does not require a prompt. Support access is one request, and voice is the only additional request. The prompt names the agent and their team, and counts down the 60 seconds it stays open; dismissing or ignoring it counts as decline. Tenant policy can narrow abilities but never pre-accept them. Every consent is recorded with the wording shown. |
Annotations stream while the agent draws and use viewport-normalized coordinates, so the in-progress stroke is visible on both sides and stays aligned when the agent’s player is scaled.
Granting Support access puts a minimized Support chat launcher in the lower-right corner of the user’s page, so they can start the conversation themselves. The first agent message opens the panel. The user can reply or minimize it, and after they minimize it, further messages increment an unread badge instead of reopening it. Chat does not need another prompt.
What the live view sends
Section titled “What the live view sends”Nothing new. It is the same masked DOM stream as the recording — no screen sharing, no video, and no extra capture on the page. When an agent attaches, the SDK takes a fresh snapshot so their console has a current frame instead of waiting for the next scheduled checkpoint.
Remote control limits
Section titled “Remote control limits”Synthetic events are not trusted by the browser: file pickers, clipboard, fullscreen, autofill, and beforeunload prompts will not fire. The agent gets a Guide fallback that highlights the target and asks the user to click. Typing into type=password, payment autocomplete fields, and anything under data-backstory-mask or data-backstory-block is blocked by policy. Every action is logged with the agent as actor and shown in the replay with a distinct cursor.
Self-hosted
Section titled “Self-hosted”The Helm chart ships LiveKit (open source) with an embedded TURN relay, so voice connects from restricted networks. Voice is audio only.