Skip to content
OneChat · In your browser

The browser assistant that asks first

OneChat now works in your own browser. Ask it to check a page, compare a few vendors, or fill something in — it opens its own tabs, uses your own logins, and asks before it changes anything. Every action approved, every site audited, off until your admin turns it on.

Two surfaces, one assistant

Beside the page, or driving the browser

A side panel, next to any page

Open OneChat beside whatever you're looking at and ask about it — "what does this page say?", "fill this in". Your full OneChat comes with it: chat history, the model picker, skills, knowledge bases and connectors. The same conversation continues on the web.

Or from the web app, driving your browser

Flip on Browser in OneChat and it works in your Chrome: it opens pages in a labelled OneChat tab group in the background, reads them, and reports back. Your own tabs are never touched — and you can drag one into the group to share it.

Because it rides your own sessions, it reaches the long tail every enterprise has: the internal tool with no API, the vendor portal nobody will ever build a connector for.

Built for a hostile page

An assistant with your sessions is worth attacking

Browser agents are a genuinely new attack surface, so the rails assume the page is hostile — and the important ones are mechanical, not matters of the model's judgment.

Consent before anything, not after

Approval is collected before an action is queued, so declining means the browser was never told to do it. You watch each consent card appear in the conversation and approve it there.

It won't type into credentials

Password, one-time-code and payment fields are refused outright. That refusal lives in the extension itself, so it holds even if a page talks the model into trying.

Redirects off an approved site are blocked

A page that sends it somewhere you didn't approve is refused mechanically — naming both origins — rather than left to the model's judgment. Page text is treated as data, never as instructions, and is DLP-scanned like any other tool output.

Off by default, granted per user, fully audited

Disabled for the whole tenant until an admin turns it on, then granted per user or group. Every action lands in an audit row — tool, site origin, outcome — recording origins only, never full URLs.

Where the line is

What it deliberately won't do

Some of these are choices, some are limits we haven't lifted yet. Either way you should hear them from us before a pilot, not discover them during one.

  • It doesn't browse on its own. You have to be there, in a live conversation — there is no background, scheduled or unattended browsing. Unattended automation is Agent Studio's job, where it's server-side and auditable.
  • It reads text and structure, not pixels. No screenshots, no visual page reading.
  • It doesn't record or replay workflows.
  • It can't upload, download, print, or open operating-system dialogs.
  • Chrome and Edge on desktop only — no Firefox, no Safari, no mobile.
  • It isn't in the Chrome Web Store yet. Entitled users install it themselves from the Help Center, loaded through Chrome's developer mode — deliberate for the pilot phase, since unlisted distribution keeps it inside entitled tenants.
  • We won't promise flawless behaviour on every site. Unusually heavy JavaScript apps can ignore synthetic input, and pages that load as you scroll can read incomplete in a background tab. It's built to tell you when it couldn't do something rather than guess — and that's a question worth answering in a pilot, on your own tools.
FAQ

Questions security teams ask first

What can OneChat do in my browser?
It reads the page you're looking at, opens pages of its own in a background tab group, and fills things in — using the sites you're already signed into, with you approving every consequential step.
Why does it help with tools we can't integrate?
Because it works the way a person does: in the browser, signed in as you. That covers internal dashboards, vendor portals and legacy admin screens that have no API and will never get a connector.
Can it act without asking me?
No. Consent is collected before an action is queued, so if you decline, the browser is never told to do it. Every consequential step needs a human click.
Will it touch my passwords?
No. It refuses password, one-time-code and payment fields, and that refusal lives in the extension rather than in the model's instructions.
What happens if a web page tries to hijack it?
Page content is treated as data, never as instructions, and the assistant reports injection attempts. Redirects to sites you haven't approved are blocked mechanically, and page text is DLP-scanned like any other tool output.
Does it browse in the background on a schedule?
No, and that's deliberate. A user has to be present with a live conversation; unattended automation belongs in Agent Studio, where it runs server-side and auditable.
Which browsers does it support?
Chrome and Edge on desktop. There is no Firefox, Safari or mobile support.
Is it on by default?
No. It's disabled for the entire tenant until an admin enables it, and then granted per user or group.
What can our admins see?
Every action it takes, as an audit row with the tool, the site origin and the outcome. Origins are recorded rather than full URLs, so an audit review stays privacy-clean.
Is it in the Chrome Web Store?
Not yet. Entitled users install it from the Help Center via Chrome's developer mode, which keeps distribution inside entitled tenants during the pilot phase.

Pilot it on your own tools

The honest way to evaluate this is one team, grants mode, and an audit review after two weeks — on the portals and dashboards your people actually live in.