botteams.ai

How does Grok Bot security work?

Every Grok Bot on an account shares one cloud computer. Browser sessions, files, and command-line credentials are available to the whole roster. A second Bot is a second job, not a vault. Deleting a Bot removes its profile, conversation, and routines. Files and signed-in sessions can remain.

Last updated

  1. 1. What is the shared-computer boundary?
  2. 2. What happens when you delete a Bot?
  3. 3. What should stay behind approval?
  4. 4. Questions people ask

What is the shared-computer boundary?

The computer is isolated to your account, not to an individual Bot. Treat a login or file placed on the computer as available to all of your Bots.

Source: docs.x.ai/grok-bot/overview, "Bots share one computer"

Do not use separate Bots as a security boundary.

Source: docs.x.ai/grok-bot/approvals-security-and-privacy, "Understand the shared-computer boundary"

That pair of sentences is the whole security model most people miss. Connectors are the same story: account-wide plugins. Read or draft in an installer is a sentence, not a lock.

What happens when you delete a Bot?

Deleting a Bot removes its profile, conversation, and the routines it owned. Files and signed-in sessions on the shared computer can remain. Sign out of sites, uninstall connectors you no longer want, and remove project files under /workspace if that work should stop being available to the rest of the roster.

What should stay behind approval?

Keep sending, publishing, purchasing, deletion, and production changes on a human yes. Take over the computer for passwords, passkeys, two-factor codes, and CAPTCHAs. Do not paste those into chat. xAI's use-cases page repeats the same stop line on every role.

The recipes on this directory ship that stop line in the prompt. They cannot enforce it. You still confirm the routine card.

Questions people ask

Does creating a second Bot isolate logins and files?

No. Every Bot on an account uses the same cloud computer. A second Bot is a second conversation and job. Treat the roster as one trust zone. Put only credentials that every Bot on the account may use.

Is the shared computer the same as my laptop?

No. The client is macOS, Windows, or iOS. The computer the Bots share is a managed cloud environment. Local-file products such as Claude Cowork are a different machine: the one on your desk.

Can a routine spend money?

If the connected app can spend, a loose prompt can spend. Keep purchases behind approval. The Expense Manager recipe drafts follow-ups and does not change reimbursements.

Related: What is Grok Bot?, Connectors, Write a profile.

Verified on 2026-08-24 against docs.x.ai/grok-bot/overview, docs.x.ai/grok-bot/approvals-security-and-privacy, docs.x.ai/grok-bot/use-cases. Recheck the live pages before you change a plan or a vendor.