Docs explain your product. OneTwoAgent also recognizes the signed-in customer, uses the account data you authorize, and makes scoped fresh backend lookups when the answer depends on what is happening right now.
Your latest CSV import (imp_8421) failed: some dates aren’t in a supported format. Export them as YYYY-MM-DD and run the import again.
What is account-aware AI customer support?
Account-aware AI customer support answers with two kinds of evidence: your product knowledge, and facts about the signed-in customer’s own account — plan, subscription, access, usage, jobs and integrations — that your backend authorizes.
OneTwoAgent receives those facts in a signed account snapshot when the customer is identified, and, when an answer depends on current state, from a scoped fresh lookup to one read-only endpoint in your backend. When the evidence or the authority isn’t there, it hands the conversation to your team.
Docs tell your AI how the product works.
Account context tells it what is happening to this customer.
Documentation can explain the rule. Support needs the customer’s reality.
The same three questions, answered from docs alone and with authorized account evidence.
Why can’t I use the Salesforce integration?
Docs-only answer
The Salesforce integration is available on eligible plans. See “Integrations by plan”.
Account-aware answer
Salesforce sync isn’t part of your Pro plan, so it isn’t available on your workspace. “Integrations by plan” lists the plans that include it.
subscription · plan Pro
access · capabilities
Help Center · Integrations by plan
Why did my latest import fail?
Docs-only answer
Common causes are unsupported date formats, missing columns and files over the size limit.
Account-aware answer
Your latest CSV import (imp_8421) failed with INVALID_DATE_FORMAT: some dates aren’t in a supported format. Export them as YYYY-MM-DD and run it again.
jobs · fresh lookup · failed
Help Center · Imports
How many imports do I have left?
Docs-only answer
You can see your usage under Settings → Billing → Usage.
Account-aware answer
You’ve used 42 of your 50 imports, so 8 are left.
usage · imports 42/50
Example workspace (Tallyworks). Account facts follow the saas_support_v1 contract.
What the agent can know about the customer.
Five account sections, each a small, typed projection. Your backend decides which sections to enable and which facts to fill — the agent only receives the data you authorize.
Plan & subscription
Which plan applies and whether the subscription is trialing, active, past due, cancelled or expired.
section: subscription
plan
subscriptionStatus
accountStatus
Access & entitlements
The customer’s role and the capabilities their account can use.
section: access
role
accountStatus
capabilities
Usage
Current usage against the limits you choose to show.
section: usage
metric
used
limit
Jobs
Recent imports, exports, syncs or other jobs: pending, running, completed, failed or cancelled.
section: jobs
id
type
state
reasonCode
Integrations
Whether each connection is connected, disconnected, pending or in error.
section: integrations
kind
state
reasonCode
These are the sections the contract supports, not data every integration exposes automatically. A section you don’t enable is unknown to the agent — not zero, and not “no access”.
Context when the conversation starts. A fresh check when the answer depends on right now.
Signed account snapshot
Your server sends a small set of facts when it identifies the customer. OneTwoAgent validates them and signs them into the identity token. Most account questions are answered from it, with no extra call.
Sent by your server in the identity exchange, signed by OneTwoAgent
Bound to one user and one workspace
Expires within 5 minutes of when it was observed
At most 2 KB, closed schema — unknown fields are rejected
Scoped fresh lookup
When an answer depends on current state, the agent asks your backend for one allowed section — and gets an up-to-date read.
One read-only HTTPS endpoint in your existing backend
One allowed section per customer turn: subscription, access, usage, jobs, integrations
Your endpoint rechecks the live session and workspace membership on every call
Results last at most 30 seconds; a 3-second deadline
Fresh lookup · valid ≤ 30 s
Snapshot observedSnapshot expires · ≤ 5 min
Fresh fields replace that snapshot section for the current turn. If the check fails or times out, the agent says it couldn’t check the current state — older facts are never presented as a live result.
How it works.
Your server vouches for who is asking. OneTwoAgent combines product knowledge with the account evidence you authorize — and only answers what that evidence supports.
Signed-in customer
Alex Rivera in your app
Your server
Identity exchange: user, workspace and the account facts you choose
OneTwoAgent support agent
One conversation per user and workspace
Evidence for this turn
Product knowledge
Help Center, website, Google Drive, files
Authorized account snapshot
plan · usage · jobs · integrations · ≤ 5 min
Scoped fresh backend lookup
get_account_status({ section })
Grounded answer
From your docs and this customer’s account, with the sources it used.
Human handoff
When evidence or authority is missing, your team takes over in the inbox.
Your backend remains the authority for account facts.
OneTwoAgent receives only the sections you enable.
Each lookup is scoped to one section for the signed-in user and workspace.
Account evidence is kept out of long-term AI memory and shared caches.
Missing facts are unknown — the agent doesn’t invent them.
Missing, expired or mismatched proof fails closed.
Account context runs in the website widget, where your app knows who is signed in.
Your backend stays in control.
OneTwoAgent never connects to your database. Your application exposes the specific support context and scoped reads the agent may use — and nothing else.
Your app
subscriptionenabled
accessenabled
usageenabled
jobsenabled
integrationsnot exposed
Authorized support contract
saas_support_v1 · signed snapshot
account lookup · schema version 1
read-only · one section per call
OneTwoAgent
Receives only enabled sections
subscription
access
usage
jobs
Integrations isn’t enabled here, so the agent can’t see it — those questions go to your team.
Explicit scope
You pick the sections and project each field yourself. The agent can only ask for a section you enabled.
Your auth, rechecked
Your endpoint verifies the live session and workspace membership on every lookup. Sign out or remove a member and the next lookup fails.
Read-only by design
No SQL, no write actions, no full records, no hidden flags or stack traces — only the closed schema your endpoint returns.
Secrets stay on your server
The identity secret and a separate read credential live in your server environment. The browser only gets a short-lived token signed by OneTwoAgent.
Your endpoint answers one section (abridged)
POST https://your-app.example/api/support/account-status
{
"version": 1,
"section": "jobs",
"subject": {
"userId": "usr_5d1c90",
"workspaceId": "ws_ridgeline"
},
"…": "operation, turn and grant bindings"
}
What happens when a signed-in customer asks about something only their account can explain.
TallyworksSigned in · Alex Rivera
Why isn’t the Slack integration working?
Slack is disconnected on your workspace — its access was revoked. Open Settings → Integrations → Slack and choose Reconnect, then approve the connection in Slack.
Help Center · Integrations
Reconnect says only a workspace owner can approve it.
Maya joined the conversation
Maya
Hi Alex, Maya here. I’ll get your workspace owner to approve the Slack connection.
01Recognizes the signed-in customeridentity tokenAlex Rivera · ws_ridgeline
02Reads your product docsknowledgeHelp Center · Integrations → “Reconnect Slack”
04Confirms the current statefresh lookupget_account_status({ section: "integrations" })
05Answers for this customeranswerAccount fact + the docs fix, with sources
06Hands off when it can’t resolvehandoffOnly an owner can approve — the agent stays quiet and your team takes over
Example workspace. The thread uses the widget’s own message styles; on a handoff the agent sends no scripted hand-over message.
Know when to answer. Know when to hand off.
Account-aware doesn’t mean the AI answers everything. It answers when the evidence and the authority support it — and brings in your team when they don’t.
The agent stops instead of guessing — it never promises a reply on your team’s behalf.
The conversation is marked as needing a reply in your shared inbox, and your team is notified.
Whoever picks it up sees the whole conversation and the sources the agent used.
1Add product knowledgeWebsite, Help Center (including a public Intercom Help Center), Google Drive and files.Knowledge docs
2Install the widgetConnect the project with the CLI — it links the widget and writes the identity secret to your server env.npx -y @onetwoagent/cli@latest init --browser
3Identify the signed-in customerYour server exchanges its own session for an identity token that lasts 15 minutes. The browser calls identify(token).
4Define the account contextAdd a saas_support_v1 snapshot to your identity exchange with the facts your customers ask about. OneTwoAgent validates and signs it.
5Add a scoped fresh lookupOne read-only endpoint for state that changes, then enable it for the sections you choose.onetwoagent account-lookup configure descriptor.json
6Test customer-specific answersAsk as a real signed-in user, then as another user and workspace, and with a section switched off.
7Bring in your teamHandoff is on by default. Your team works the shared inbox; the agent hands conversations over when it should.
AI customer support that answers with your product knowledge and with facts about the signed-in customer’s own account — such as plan, access, usage, jobs and integrations — that your backend authorizes. It can explain what is happening for this customer, not only how the product works.
Can an AI support agent know which customer is signed in?
Yes — in the OneTwoAgent website widget. Your server exchanges its own session for a widget identity token that lasts 15 minutes, and the browser calls identify(token). Each conversation is bound to one user and one workspace; the identity secret never reaches the browser.
Can OneTwoAgent answer using customer account data?
Yes. It uses the account facts your backend authorizes — from a signed account snapshot and, for current state, from scoped fresh lookups to your backend. The supported sections are subscription, access, usage, jobs, integrations.
Does OneTwoAgent need access to my database?
No. It never connects to your database. Your backend sends a small snapshot of the facts you choose and, optionally, answers read-only lookups for one allowed section at a time from your own endpoint, using your existing permission checks.
How does OneTwoAgent get live account data?
When an answer depends on current state, the agent requests one allowed section from a single read-only HTTPS endpoint in your backend. Your endpoint rechecks the live session and workspace membership, then returns a closed schema. Results are valid for at most 30 seconds, and there is at most one lookup per customer turn.
What is the difference between account context and a fresh lookup?
Account context is a signed snapshot your server provides when it identifies the customer; it expires within 5 minutes and answers most questions with no extra call. A fresh lookup is an on-demand read of one section when the answer depends on what is happening right now. Fresh results replace that snapshot section for the current turn.
What customer data can OneTwoAgent read?
Only what you expose: plan and subscription status, account status, role and capabilities, usage metrics with limits, recent jobs with their state, and integrations with their state — each with an optional reason code. Anything you leave out is unknown to the agent. Credentials, tokens, stack traces and other users’ data must never be included.
Is customer account data stored in conversation memory?
No. Account proof stays in the widget’s memory, not in local storage or URLs. Long-term AI summaries, shared caches and raw replay captures are disabled for account turns, and earlier messages are never treated as current account facts. Your inbox keeps the conversation history.
Can the AI hand off when it doesn’t have enough account information?
Yes. When a section isn’t exposed, the current state can’t be confirmed, the request needs human authority or the customer asks for a person, the agent stops instead of guessing. The conversation is marked as needing a reply in your shared inbox, your team is notified, and a teammate takes over with the full context.
Can I use OneTwoAgent with my existing SaaS backend?
Yes. You keep your auth and data model. The CLI and its coding-agent skill adapt the integration to your existing server session; you add the snapshot to your identity endpoint and, optionally, one read-only lookup endpoint.
Let your support agent know the customer.
Start with your product knowledge. Connect signed-in customer context when you’re ready. 14-day free trial · 50 AI conversations · no card.