Grok Bot approvals, shared logins, and what not to trust yet
Grok Bot's computer is shared across all of your Bots. How to grant access, what should still need approval, and the security questions to ask before it signs into money or clients.
Grok Bot’s power is the same fact as its risk: it has a computer, and that computer can sign in like you.
xAI’s docs do not hide the shared-machine model. All Bots on your account use one persistent cloud computer. They share files, sessions, and logins so handoffs work. They do not get separate vaults because they have separate names.
Short answer: Treat every login on the Grok Bot computer as visible to every Bot you create. Start with read-and-draft. Require approval on send, pay, post, and delete. Keep payroll, trust money, and production keys off that machine until the routine is proven. Teams should run the admin setup in the Cursor dashboard before anyone grants Gmail.
Approvals that actually mean something
“Come back when you need me” is the product promise. Your job is to define when.
Good gates:
- Anything that leaves the building: email, LinkedIn, SMS, social, invoices.
- Anything that changes a system of record in bulk.
- Anything that spends money.
Bad gates:
- Asking the Bot to ping you every 15 minutes. Early users said the Bots noticed. That is micromanagement, not security.
- No gate at all because the demo was smooth.
Show the Bot the workflow once. Save it as a routine. Correct the first ugly drafts in the thread. Then widen autonomy. Trust is supposed to compound. It should not start at 100%.
Shared computer, shared blast radius
Parallel Bots are not parallel sandboxes. A research Bot and a finance Bot on the same account share the browser jar. If you would not give your intern both logins on one laptop, do not give two Bots both logins on one VM.
Practical split for a small firm:
- Account A / computer: marketing and CRM drafts.
- Do not put banking on that computer.
- Phone intake stays on Twilio + the receptionist, which is a different credential set.
Team rollout
Cursor Teams Premium admins get a Grok Bot page: privacy mode, dedicated desktop, API pricing, pooled billing, premium seats. Existing team privacy mode, MCP policy, and rules apply. There is no separate Grok Bot plugin allowlist.
If you are not the admin, do not “just sign into HubSpot” on a shared workspace Bot computer. That is how shadow IT used to happen with browser extensions.
This is not a reason to freeze
It is a reason to sequence. Public site first — quoted web work. Phone coverage second. Grok Bot third, on the tools you can afford to have a smart intern inside.
Ask for the quote or map the access list before you dump every portal onto one machine.
FAQ
Do all Grok Bots share the same computer? +
Yes. Docs are explicit: Bots share files, browser sessions, and app logins on one user-scoped machine. A login you place there is available to every Bot on the account. Each Bot gets its own screen so they can work in parallel, not a separate security boundary.
Should Grok Bot send email without asking? +
Not in week one. Drafts for approval until the voice and the edge cases are boring. Then turn sending on for the routine you actually trust.
Is Grok Bot okay for client data? +
It depends on the data, the contract, and whether you can live with xAI's subprocessors. There is no admin model picker; routing is product-managed. If your contract restricts subprocessors, talk to the account team before rollout.
What should never go on that computer first? +
Payroll, trust accounts, production deploy keys, and anything where a silent error scales into a lawsuit. Demonstrate a read-only or draft-only path first.