We only do this with consent from the application owner - the use case is typically companies who don’t have an AI agent yet who want fast path to get one.
Yup just another user account. It can work without this as well (we support ingesting other resources such as help center articles, pdfs, etc.) but at that point it's no different from any other (dumb) AI chatbot out there that just spits out a bunch of itemized bullets.
Even with an API spec it wouldn't "just work". You'd still need to handle authentication and have a place to manage which APIs you want the in-app agent to have access to / when to call a given tool.
And believe it or not, even big companies with big eng teams don't have API specs available for their applications ¯\_(ツ)_/¯
We use a browser-based agent to learn all the APIs and turn them into skills. Most users will run this in a staging/test account to create all the recipes/blueprints. Our agent is also instructed to not take any destructive actions - but of course LLMs make mistakes (hence the test account :) ).
Our customers run the training on their own applications using a demo or staging environment. Then they install the in-app agent you see in the demos and turn on the tool calls they like. All the API calls are executed client side and never touches any of our servers.
Currently we work will all kinds of software products, so haven't settled on any specific industry yet. But we do see a lot of interest from software with less technical end users.
And we haven't really seen security or privacy issues in terms of competitor leakage. There is more concern around customer data and privacy, and in that regard, we invest heavily in security and have safeguards to help minimize the risk of any customer data issues.
This seems like something that was evident for AI to disrupt into. I recently went through an entire underwriting process when getting my first mortgage and honestly was shocked with how slow and old-fashioned the process was. Even had to fax a few documents (!?).