Privacy & control

Co-browsing for Customer Support: Consent First

Plan a guided support session around a narrow purpose, understandable permissions, deliberate actions, and an explicit ending.

Consent-led customer support: neon browser-themed editorial illustration branded SharedBrowser.com.

Co-browsing can be a useful model for guiding someone through an unfamiliar online process, but a support session is not simply a shared view. It is an interaction between people with different levels of knowledge, authority, and access. A customer may not understand which parts of the screen are visible, whether another person can act, or what information will remain after the conversation.

A responsible support workflow should make those boundaries understandable before the session begins. This guide outlines a consent-led approach to planning a co-browsing or screen-sharing interaction. It does not claim that every provider supports the same controls, and it does not replace a support organization's security, privacy, or customer-care procedures.

Define the problem before choosing the channel

Ask what the person is trying to do and where they are getting stuck. A clear written instruction or a relevant help page may solve the problem without a shared session. Use co-browsing or screen sharing when a common view would help resolve a specific ambiguity, not merely because the option is available in the support toolbar.

Set a narrow objective: locate a setting, understand an error message, or confirm the next step in a supported workflow. Avoid beginning with an open-ended request to show the entire device. The narrower objective helps the agent choose an appropriate sharing mode and helps the customer understand why the session is being proposed. Our customer-support use case illustrates this scope-first approach.

Explain the actual mode in plain language

Tell the participant what the selected mode allows the agent to see and do. Distinguish viewing from remote control and distinguish a supported page from a broader device view. Describe the controls the participant can use to pause or end the session. Do not rely on a label such as “secure assist” to communicate the boundary.

Specific products can separate these steps. For example, Google Cloud's Screen Share documentation describes consent dialogs for an initial session and for subsequent remote-control or full-device-access requests, along with an end-session control. That is an example of a documented workflow, not evidence that all co-browsing tools use the same model. Check the provider and mode actually being deployed.

Offer a clear choice and explain an alternative route when one is available. A person should not have to guess whether declining a session means losing all support. Ask whether they are comfortable proceeding after explaining the scope. Leave room for questions and avoid treating a hurried agreement as a substitute for understanding.

Use the service's actual consent mechanism where required, and follow the organization's process for any additional records. Do not make the agent's script broader than the product's controls. If the session scope changes, explain the new scope before requesting the corresponding permission. The co-browsing comparison provides language for separating shared viewing, navigation, and control.

Prepare a focused view

Before sharing, help the participant identify the intended page or application. Suggest closing unrelated sensitive material and checking visible notifications when appropriate to the selected mode. Avoid asking the customer to expose a broader view simply because it is easier for the agent. If a narrow mode cannot support the task, explain that limitation and follow the approved escalation route.

The agent should prepare too. Have the relevant procedure available, know the session controls, and understand which actions must remain with the account holder. A support session should not become an improvised exploration of a customer's account. When troubleshooting needs a test environment, use an approved sample account rather than asking the customer to reproduce an unnecessary sensitive action.

Keep consequential actions with the account holder

Viewing a page and submitting a change are different responsibilities. For actions that affect an account, payment, access, or another important setting, explain the proposed step and let the account holder review it. Where practical and consistent with the approved process, have that person perform the final action themselves rather than treating remote control as blanket authority.

Never ask a person to reveal a password, recovery code, or one-time authentication code to make the session easier. If authentication is required, use the appropriate private process and pause or stop sharing as needed under the tool's documented behavior. Do not assume that a visually masked field is excluded from every technical capture path. Confirm sensitive-field handling before relying on it.

Narrate the work and check understanding

Explain what you are looking at and why. Use the visible label of a control rather than “click over there.” Ask the participant to describe what they see when the agent's view is incomplete. Keep the pace appropriate to the person rather than moving quickly through a familiar interface while they struggle to follow.

At a decision point, summarize the available options and the consequence of the next step. Avoid implying that the customer has agreed merely because a cursor moved or a page changed. A short check of understanding can reveal that the underlying problem differs from the agent's initial assumption. The session should help the person regain control of the task, not leave them dependent on unexplained actions.

Handle unexpected information calmly

Prepare a response for the moment when unrelated or sensitive information appears. Pause or end the session using the appropriate control, explain what happened without repeating the information unnecessarily, and follow the organization's reporting process where required. Do not take additional screenshots or copy the material into a ticket simply to document that it appeared.

If the session moves outside the approved scope, stop and reassess. A request to help with one website does not automatically authorize exploring unrelated applications or files. When the problem cannot be resolved within the permitted workflow, use an established escalation path. Clear limits are part of good support, not an obstacle to it.

Decide what belongs in the support record

A useful ticket records the problem, relevant non-sensitive observations, the action taken, and the outcome. It does not need every detail visible during the session. Distinguish a concise case summary from a recording, transcript, or screenshot collection. Confirm which recording features are enabled and follow the applicable notice, access, and retention requirements before using them.

Avoid promising that ending the session deletes every retained artifact. Check the provider's documented behavior and the organization's configuration. Keep access to any retained material limited to the people and purpose that justify it. Our workspace permissions guide offers a broader checklist for separating viewing, editing, exporting, and retaining information.

During training, rehearse the ordinary end of a session as carefully as the beginning. Ask the agent to explain the outcome, point out the end control, and record a concise case note using only sample data. A rehearsed closing sequence can reveal uncertainty about retained artifacts or continuing access before that uncertainty affects an actual customer.

End explicitly and leave a useful next step

Tell the participant when the session has ended and verify the visible end state where the tool allows it. Summarize what was resolved and what remains open. Provide a reference to the relevant help material or a clear next action through the approved support channel. Do not leave the person wondering whether someone can still see or control the device.

A strong co-browsing workflow begins with a narrow problem and ends with the customer understanding the outcome. Explain the actual mode, obtain the appropriate consent, keep consequential actions deliberate, and limit the record to what is needed. These habits should be tested with the real product and reinforced in training. Shared visibility is useful only when the boundaries around that visibility are equally clear.