Grok Bot security
Grok Bot Security, Privacy and Admin Controls
Grok Bot gives each user one managed cloud computer shared by all of that user's Bots. Files, browser sessions, and command-line credentials cross Bot boundaries, so use least privilege, human credential handoffs, narrow approval rules, and source-side revocation. Privacy Mode (Legacy) blocks Grok Bot, and the current product lacks a complete Bot-action audit view.
On this page
- What is Grok Bot's security boundary?
- How do Grok Bot approvals and Auto Review work?
- How should Grok Bot handle passwords, passkeys, and secrets?
- Does Grok Bot support Cursor Privacy Mode?
- Which Grok Bot controls do team admins have today?
- How do you remove Grok Bot access and working data?
- What should an enterprise Grok Bot pilot verify?
What is Grok Bot's security boundary?
The security boundary is the user, not the named Bot. Each team member gets one managed Linux virtual machine, and all of that member's Bots share its files, browser sessions, command-line credentials, and local-computer permissions. Each Bot has a separate screen for parallel work, but those screens are work surfaces rather than isolated machines.
- Resource
- Files in the cloud workspace
- Shared across one user's Bots?
- Yes
- Operational consequence
- Use project folders and remove sensitive temporary files
- Resource
- Browser cookies and signed-in sessions
- Shared across one user's Bots?
- Yes
- Operational consequence
- A login performed for one Bot becomes available to the roster
- Resource
- Command-line credentials
- Shared across one user's Bots?
- Yes
- Operational consequence
- Do not assign Bots as if they had separate credential scopes
- Resource
- Screens and conversations
- Shared across one user's Bots?
- No
- Operational consequence
- Work can run in parallel, but access remains shared
- Resource
- Hosted MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. sign-in tokens
- Shared across one user's Bots?
- Handled by Cursor's backend
- Operational consequence
- The computer does not store those tokens
| Resource | Shared across one user's Bots? | Operational consequence |
|---|---|---|
| Files in the cloud workspace | Yes | Use project folders and remove sensitive temporary files |
| Browser cookies and signed-in sessions | Yes | A login performed for one Bot becomes available to the roster |
| Command-line credentials | Yes | Do not assign Bots as if they had separate credential scopes |
| Screens and conversations | No | Work can run in parallel, but access remains shared |
| Hosted MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. sign-in tokens | Handled by Cursor's backend | The computer does not store those tokens |
One computer is assigned to each member. Team membership and Bot names do not create additional computer isolation.
This boundary is convenient for handoffs. One Bot can continue from a file another saved, and a browser login does not need to be repeated for every role. The cost is that a Bot roster cannot double as a permissions design. If two jobs need different access, use separate source-system accounts and scopes, or keep the more sensitive job outside that user's Grok Bot computerThe persistent cloud computer shared by all Grok Bots on one user's account, including its files, browser sessions and command-line credentials. Press Enter for the full definition..
The local Mac or Windows computer is separate. A Bot can run commands, read files, or move files there only when local execution is enabled under the member's policy. The default personal setting is Ask every time. SpaceXAI recommends Never allowed unless the Bot has a specific reason to work on local files.
This exact topic is a hands-on Lesson: Privacy and Data Governance — about 6 minutes, free to read.
How do Grok Bot approvals and Auto Review work?
Put the boundary in the task before the Bot starts. Sending a message, publishing content, purchasing, transferring money, deleting data, changing permissions, modifying production, and accepting legal terms should each have an explicit stop. An approval governs the proposed action. It cannot undo work the Bot already completed.
When an action stops for review, inspect the target, scope, inputs, and values. Desktop offers Allow once, Deny, and an Always allow option that can save a matching rule. On iPhone, the equivalent immediate controls are Approve once and Deny. Ask for a draft or a plain-language explanation if the card does not make the effect clear.
- Control
- Require Approval rule
- What it does
- Stops a matching action for the user when Auto Review enforcement is available
- What it does not prove
- That the proposed result is correct
- Control
- Always Allow rule
- What it does
- Lets a matching action proceed unless automated review finds another reason to stop
- What it does not prove
- That future website behavior will match today's rule
- Control
- Team rule
- What it does
- Places scoped guidance in the Bot's context
- What it does not prove
- Hard enforcement; SpaceXAI directs admins to Auto-review instructions for that
- Control
- Human approval
- What it does
- Authorizes the shown operation once
- What it does not prove
- Rollback for earlier work or unseen side effects
| Control | What it does | What it does not prove |
|---|---|---|
| Require Approval rule | Stops a matching action for the user when Auto Review enforcement is available | That the proposed result is correct |
| Always Allow rule | Lets a matching action proceed unless automated review finds another reason to stop | That future website behavior will match today's rule |
| Team rule | Places scoped guidance in the Bot's context | Hard enforcement; SpaceXAI directs admins to Auto-review instructions for that |
| Human approval | Authorizes the shown operation once | Rollback for earlier work or unseen side effects |
If Require Approval and Always Allow both match, Require Approval wins.
Auto Review is model-based. SpaceXAI says it should complement least privilege and explicit approval boundaries, which is the right way to read the feature. A narrow rule such as requiring approval before an external email has a recognizable target. An allow-everything browser rule depends on every visited site keeping the same actions and labels over time.
Personal Auto-review rules are stored on the current desktop and synced to its Grok Bot computerThe persistent cloud computer shared by all Grok Bots on one user's account, including its files, browser sessions and command-line credentials. Press Enter for the full definition.. Verify them separately on another desktop installation. That detail is easy to miss in a rollout where two machines sign into the same account and everyone assumes the rule set followed automatically.
How should Grok Bot handle passwords, passkeys, and secrets?
Enter passwords, passkeys, two-factor codes, CAPTCHAs, and payment confirmations yourself. Open Agent Computer, take control for the sensitive step, then return control after you confirm the account and scope. Do not place a password or one-time code in ordinary chat.
- 1Connect only the service the workflow needs, using a scoped service account where the provider supports one.
- 2Take control of the computer for authentication and verification.
- 3Review the first proposed read or write action after sign-in.
- 4Keep sending, publishing, purchasing, deletion, and production changes behind approval.
- 5Sign out and revoke the source-side authorization when the work ends.
A supported connector may present a secure secret request. The value is masked, excluded from the transcript, and not shown to the model. Treat that as a connection-specific handoff rather than a place to store unrelated secrets. For hosted MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. servers, the team docs say sign-in tokens remain with Cursor's backend, which performs those calls on the computer's behalf.
Hardware security keys work through forwarded WebAuthn prompts from the computer browser to the member's desktop app and physical key. Windows support is still rolling out. Device-trust agents such as Okta FastPass do not run natively inside the managed Linux VM, so enterprise identity policy needs a separate review rather than an assumption that the laptop's posture carries over.
Does Grok Bot support Cursor Privacy Mode?
Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. requires cloud data storage and does not support Privacy Mode (Legacy)A Cursor data setting that blocks Grok Bot because the product requires cloud data storage. Press Enter for the full definition.. Standard Cursor privacy and data-sharing settings govern the account, including the applicable training opt-out. While a member belongs to a team, the team's privacy mode applies and the member cannot weaken it.
Do not translate that into a stronger retention promise. SpaceXAI says backend retention and account deletion follow the applicable Cursor terms. The Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. docs do not publish a special zero-retention mode or a separate fixed retention period for this product. Review Cursor's current privacy policy, security information, and contract before placing regulated data on the computer.
The product also manages model choice. Members and admins cannot select or block individual Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. models from a picker. Each surface routes across a fixed set with automatic failover, usage analytics show the model that served a request, and billing follows that serving model. If a contract limits subprocessors, the team docs direct the customer to its account team before rollout.
Members on a Legacy Privacy team see that the mode blocks Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. and are told to ask an admin. Decide whether the product fits the organization's data policy before changing the team setting.
Which Grok Bot controls do team admins have today?
Admins manage Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. from the Cursor dashboard and inherit several existing Cursor controls. Cursor SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and team membership apply to sign-in. Team privacy mode, MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. configuration, team rules, account-level on-demand controls, and the Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition. toggle shape what members can do. Grok Bot-specific setup also covers the dedicated computer, billing, model availability, and Premium seats.
- Control
- Enable or disable Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition.
- Available now?
- Yes
- Boundary
- Organization control in the Cursor dashboard
- Control
- SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and team membership
- Available now?
- Yes
- Boundary
- Applies to Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. sign-in, not every third-party site inside the VM
- Control
- MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. server policy
- Available now?
- Yes
- Boundary
- Disable globally, allow or deny servers, control member-added servers, require network allowlist
- Control
- Team rules scoped to Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition.
- Available now?
- Yes
- Boundary
- Context guidance; use Auto-review instructions for enforcement
- Control
- Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. model allowlist
- Available now?
- No
- Boundary
- Model selection and failover are managed by the product
- Control
- Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition.-specific spend cap
- Available now?
- No
- Boundary
- Account-level on-demand controls still apply
- Control
- Bot-action audit view
- Available now?
- Coming
- Boundary
- Spend and usage are visible today, complete action audit is not
- Control
- Team ceiling for local execution
- Available now?
- Coming
- Boundary
- Members have personal policy now; planned ceiling is not a current control
| Control | Available now? | Boundary |
|---|---|---|
| Enable or disable Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. | Yes | Organization control in the Cursor dashboard |
| SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and team membership | Yes | Applies to Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. sign-in, not every third-party site inside the VM |
| MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. server policy | Yes | Disable globally, allow or deny servers, control member-added servers, require network allowlist |
| Team rules scoped to Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. | Yes | Context guidance; use Auto-review instructions for enforcement |
| Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. model allowlist | No | Model selection and failover are managed by the product |
| Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition.-specific spend cap | No | Account-level on-demand controls still apply |
| Bot-action audit view | Coming | Spend and usage are visible today, complete action audit is not |
| Team ceiling for local execution | Coming | Members have personal policy now; planned ceiling is not a current control |
The distinction between available and coming controls matters in an enterprise approval packet.
Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. follows the team's existing pluginA Cursor marketplace package that bundles MCP servers and skills (sometimes sub-agents and hooks); one click installs all of it into your Cursor instance. Press Enter for the full definition. and MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. policy. There is no separate plugin-policy layer. Admins can disable all MCP commands, allow or deny servers, decide whether members can add servers, and require each server address to appear on the team network allowlist. When policy blocks a server, the Plugins page marks it Disabled by team admin and refuses sign-in.
Organization admins can inspect and remove member computers. Team admin rights alone are not enough because one computer spans every team that member belongs to. Kill removes the running VM but preserves durable storage, and the member's next session creates a fresh computer. A member reset also recreates the machine while keeping durable data.
Network-restricted organizations should request the current static egress IP ranges from their account team. Some websites block datacenter addresses. SpaceXAI suggests allowlisting those ranges on services you control or trying the beta option that routes computer traffic through the member's computer, where appropriate for policy.
How do you remove Grok Bot access and working data?
Remove access in every layer that granted it. Deleting or hiding a Bot is only the conversation layer. Shared-computer files, browser sessions, connector authorization, and routines each have their own cleanup path.
- 1Pause or delete routines that could reopen a source or repeat an action.
- 2Sign out of websites on the shared computer.
- 3Uninstall connectors and revoke authorization in the source service.
- 4Remove sensitive project files from
/workspace. - 5Hide a Bot if its history may still be useful, or delete it when its profile, conversation, and routines should go.
- 6Use Cursor account settings for an account-deletion request.
Deleting a Bot removes its active profile, conversation, and routines. It does not remove files or browser sessions shared on the computer. Hiding is lighter still: it only removes the Bot from the main sidebar and does not pause work or routines. Check the routine list before treating either action as deprovisioning.
Revocation in the source service is the strongest proof that a connector or session can no longer act there. A local sign-out is useful, but the provider's authorization page is where you can see and remove the grant. Keep that readback with the offboarding record for sensitive tools.
What should an enterprise Grok Bot pilot verify?
Pilot a read-heavy workflow with a small user group and a source system you can revoke quickly. The result should be independently reviewable, the external-action boundary should fire in a test, and the team should know which current controls are still absent. That is enough to evaluate the product without treating beta controls as finished enterprise governance.
- Confirm Privacy Mode (Legacy)A Cursor data setting that blocks Grok Bot because the product requires cloud data storage. Press Enter for the full definition. is off only after the data-policy owner approves the change.
- Document the fixed model and subprocessor route with the Cursor account team.
- Use a scoped test account and verify source-side revocation before inviting users.
- Test a Require Approval rule on a safe external action and capture the exact card shown to the member.
- Review MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. allowlists, network egress, third-party sign-in, and local-computer policy separately.
- Record that the Bot-action audit view, product-specific spend cap, and team local-execution ceiling are not available today.
- Define a cleanup owner for routines,
/workspace, browser sessions, and connectors at pilot end.
The audit gap deserves its own decision. Spend and serving-model usage are available, while the complete action view is still coming. If the workflow needs a tamper-resistant record of every action for compliance, a conversation transcript and dashboard total do not prove that requirement. Keep the workflow out of scope or add an authoritative log in the source system.
Success should mean a useful output, an approval that stopped where expected, and a clean revocation. Speed is interesting after those three hold. Our setup tutorial provides the first-task pattern, and the Grok BotAn early AI teammate product from SpaceXAI and Cursor that works across apps on a persistent cloud computer and asks for approval on selected actions; launch materials describe it as beta, but Cursor says Beta Services terms do not apply. Press Enter for the full definition. pillar keeps product and model boundaries in one place.
Frequently asked questions
Are separate Grok Bots isolated from each other?
No. All Bots for one user share one cloud computer, including files, browser sessions, and command-line credentials. Separate screens and conversations support parallel work but do not create separate security boundaries.
Does Grok Bot support Privacy Mode (Legacy)?
No. Grok Bot requires cloud data storage, and Privacy Mode (Legacy) blocks the product. Standard team privacy settings govern data sharing and training choices for members who can use it.
Can a team restrict which models Grok Bot uses?
No. Grok Bot uses a fixed set of models for each surface with automatic failover. Members and admins do not get a model picker or per-team model list. Contact the Cursor account team if a contract restricts subprocessors.
Does Grok Bot have an audit log?
Spend and usage are visible in the dashboard today, including the model that served a request. SpaceXAI says an audit view of Bot actions is coming, so the current product does not yet provide that complete view.
Does deleting a Grok Bot delete its files and logins?
No. Deleting a Bot removes its active profile, conversation, and routines, but shared-computer files and browser sessions may remain. Sign out, revoke connectors at the source, and remove sensitive files separately.
Can Grok Bot run commands on my local computer?
Only when local execution is enabled under the member's policy. The default personal setting is Ask every time, and each local action goes through Auto Review. A planned team-level ceiling is still coming.
Sources & last verified
- Cursor Help: Getting started with Grok Bot
- SpaceXAI Docs: Approvals, security, and privacy
- SpaceXAI Docs: Grok Bot for teams and enterprises
- SpaceXAI Docs: Use the computer and apps
- SpaceXAI Docs: Skills and routines
- Cursor Privacy Policy
- Cursor Security
Cursor ships frequently. Facts verified against primary sources on August 14, 2026.
Keep reading
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.