Getting started
Add Ablehand to your app in about fifteen minutes. During the design-partner program we set up the account and configuration with you; you add one script tag.
What you need
- A web app your users sign in to (any stack: React, Vue, server-rendered, all fine).
- The ability to add a
<script>tag to its pages. - The list of origins it runs on, e.g.
https://app.example.comand a staging origin.
1. Get a site key
We issue a site key for your origins and send you the tag. The key is a public identifier, like an analytics key: it only lets the assistant make decisions for pages on your registered origins, and it can be rotated at any time.
2. Add the tag
<script src="https://ablehand.ai/nav.v0.1.0.js"
integrity="sha384-…" <!-- we send the current hash with your key -->
crossorigin="anonymous"
data-site-key="pk_…"
data-mode="guide"></script>
Pin the versioned file so nothing changes under you; we tell you when a new version is available. If your site sends a Content-Security-Policy, add:
script-src … https://ablehand.ai;
connect-src … https://ablehand.ai;
No unsafe-inline or unsafe-eval is needed. The widget renders inside a
closed shadow root and never touches your page's styles.
3. Choose a mode
- guide (start here): the assistant highlights each step and narrates it; the user performs it, or taps "Do it for me."
- do: it performs the steps, asking before anything consequential.
- hybrid: it does the reversible steps and guides or confirms the rest.
Set it on the tag with data-mode. Most partners run Guide for the first two
weeks, then switch specific tasks to Do.
4. Tell it where things are
Ablehand reads your live pages, so there is nothing to author. Two things help it on day one:
- Hints: one-line nudges we add to your configuration, like "Billing lives under Settings, Billing" or "Never open the Danger Zone." These fix most early misses without any code.
- Guardrails: which kinds of actions are allowed (click, type, select,
submit, navigate), labels it must never touch (e.g. "Delete account"), and
paths it must never enter (e.g.
/admin). Consequential actions always ask the user first.
Send us the three to five tasks you most want it to handle and we configure these with you.
5. Check it works
- Load a page with the tag: the launcher appears bottom-right.
- Open it and try a goal whose words appear on the page ("open settings").
- Try a real user phrasing for one of your target tasks.
- Watch the narration; each step names the control it used.
What it will never do
- Read or send passwords, payment fields, hidden inputs, cookies, or tokens.
- Act outside your registered origins.
- Perform an irreversible action without asking the user.
- Exceed what the signed-in user could already do by clicking.
Details in Security & trust and Trust & data handling.
What you'll see
A weekly readout during the pilot: goals asked, how many were resolved, where users got stuck, thumbs-up rate, and the before/after numbers we agreed on.