The ghost browser experience
The planned launch experience: selected task information, private human decisions and trusted action on the real website.
Help with the task, keep control of the decisions
Situation's planned ghost browser experience gives an agent a focused task view while you retain a private place to decide. The real website stays on the trusted side. You explain the purpose, choose what information and actions are permitted, and review consequential choices.
Situation is prelaunch. This guide describes the experience we are designing around people’s intent, privacy and choices.
Three connected views
| View | Its role in the intended experience |
|---|---|
| Agent's task view | Present selected task information and defined actions so the agent can help within the purpose you chose. |
| Your private decision view | Let you review consequential details and approve the exact choice, with a fresh decision when important details change. |
| Trusted website view | Keep the real website, credentials and private page context on the trusted side, where software checks permitted actions. |
The task view is designed separately from the private page. Its boundary must account for what the agent can actually read, including page structure, accessibility information, styling, resources and errors. Visual hiding alone does not establish that information was excluded.
Explain what you want, then settle the choices
You should not need to know every hidden requirement before asking for help. Situation's direction is to uncover assumptions, ask useful questions and preserve your answers as explicit decisions.
What may the agent see? Which account is involved? May it prepare a choice, or commit to it? What changes should bring the decision back to you? Those choices should become rules software checks, rather than permission an agent invents.
Preparing a choice is different from committing to it
Imagine asking an agent to prepare a cart on a supported website. It could compare the permitted choices and bring the result back for review. Preparing the cart, accepting an order and paying are distinct permissions.
A person should be able to grant useful authority for a particular task, keep private details in the private view and decide how far the agent may go. The same principle applies to a plan, a reservation or shared work: being able to use a tool does not settle whose wishes it follows.
Boundaries follow the situation
The intended authority belongs to the person, workspace, website and purpose involved. It needs a duration, a way to withdraw it and a clear account of actions and results. Signing in should establish identity without becoming permanent permission to act everywhere.
This is the connection to Personal Programming Interfaces: people's chosen intent, permissions and privacy become explicit rules. Personal agents can help each of us; social agents can help us work together, within boundaries the people involved understand and choose.
Understand information use
A selected view still needs care. A public-looking field can contain private facts, and allowing an action does not establish another person's consent to disclose information. The retailer, service or model provider may also process information under its own conditions.
Ending authority cannot recall information already received. Privacy boundaries explains actual feature disclosures, browser permissions, retained copies and other limits. Our vision explains why people should remain at the center as agents act.