6research, operations, documents, browsing, and automations. This page is for6research, operations, documents, browsing, and automations. This page is for
7team and organization admins rolling Grok Bot out. Security reviewers should7team and organization admins rolling Grok Bot out. Security reviewers should
8start with [Grok Bot security](/grok-bot/security) and the8start with [Grok Bot security](/grok-bot/security) and the
9[Grok Bot security FAQ](/grok-bot/security-faq), and members who want to9[Grok Bot security FAQ](/grok-bot/security-faq). Members who want the approval
10understand the approval model they work inside can start there too.10model should start there too.
11 11
12## Availability12## Availability
13 13
14| Plan | Access |14| Plan | Access |
15| --- | --- |15| --- | --- |
16| Individuals | Included with every paid Cursor plan (Pro, Pro+, and Ultra), through an individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+ link, or with a one-time free trial |16| Individuals | Included with every paid Cursor plan, or through an individual SuperGrok link |
17| Teams | Included; every member has access, and usage follows the seat's allowance |17| Teams | Included; every member has access, and usage follows the seat's allowance |
18| Enterprise | Contact your Cursor account team to enable Grok Bot for your organization |18| Enterprise | Enable Grok Bot for your team from your dashboard |
19 19
20That table is product access, not the admin control list. Grok Bot is included20That table is product access, not the admin control list. Grok Bot is included
21on Teams, and several settings are Enterprise only and do not appear for21on Teams. Several settings are Enterprise only and do not appear for
22self-serve Teams. The [admin controls](#admin-controls) table names each one.22self-serve Teams. [Admin controls](#admin-controls) marks each one.
23 23
24[Plans and billing](https://cursor.com/help/grok-bot/plans) is the canonical24[Plans and billing](https://cursor.com/help/grok-bot/plans) is the canonical
25plan and usage matrix.25plan and usage matrix.
26 26
27## Enabling Grok Bot for your team
28
29On the Teams plan, Grok Bot is enabled by default, and every member has access
30without any admin action. It stays off for teams on Privacy Mode (Legacy) or on
31a [legacy request-based plan](https://cursor.com/docs/models-and-pricing#legacy-request-based-pricing).
32There is no switch to turn it off.
33
34On the Enterprise plan, an admin turns it on from
35[Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot). Once
36enabled, you can give access to all team members or limit it to specific
37groups with **Manage Group Access**. Turning Grok Bot off blocks every member
38without deleting their computers.
39
40Admins on either plan can bring members in with **Invite Team** on the Grok Bot
41page. Existing Cursor users on your team get an email with a download link. New
42users get an invitation to your Cursor team, by email or invite link, that also
43points them to Grok Bot. Teams that manage membership through SCIM see only the
44existing-users option.
45
46## Before you roll out
47
48* Move off Privacy Mode (Legacy). That setting blocks Grok Bot entirely, and
49 you are prompted to change it before enabling. Check the privacy setting in
50 Team Settings.
51* Plan for shared egress addresses. If your company restricts services by
52 source IP, see [static egress IPs](/grok-bot/security#static-egress-ips).
53* Clear your gateway. If member devices sit behind Zscaler or another
54 TLS-inspecting proxy, allow Cursor's domains, including the nested
55 `*.*.cursorvm.com` pattern, and exempt them from inspection before members
56 connect. See
57 [Configure TLS-inspecting proxies](/grok-bot/proxies).
58* Decide how members sign in to company tools from the computer. See
59 [identity and sign-ins](/grok-bot/security#identity-and-sign-ins).
60* Review the policies Grok Bot inherits: Team Rules and the connector policy on
61 every plan, plus team Auto-review rules and the MCP allowlist on Enterprise.
62
27## Architecture63## Architecture
28 64
29### How Grok Bot is built65### How Grok Bot is built
30 66
31Grok Bot is a computer-use agent that operates applications, browsers, and67Grok Bot is a computer-use agent that operates applications, browsers, and
32development environments. It runs in Cursor's cloud, and each user's work68development environments. It runs in Cursor's cloud, and each user's work
33executes on a dedicated cloud computer. The desktop app (macOS, Windows, and69executes on a dedicated cloud computer. The desktop and mobile apps are thin
34Linux) and the mobile app (iOS and Android) are thin clients for chat, review,70clients for chat, review, and approvals.
35and approvals.
36 71
37The security model rests on four principles:72The security model rests on four principles:
38 73
39* Per-user isolation: each user's work runs in a dedicated Firecracker microVM,74* Per-user isolation. Each user's work runs in a dedicated Firecracker microVM,
40 a micro virtual machine with hardware-level separation from other users.75 a micro virtual machine with hardware-level separation from other users.
41* No access by default: a Bot can use only the accounts and plugins the user or76* No access by default. A Bot can use only the accounts and plugins the user or
42 team grants it.77 team grants it.
43* Human approval gates: sensitive actions require user approval, evaluated by78* Human approval gates. Sensitive actions require user approval, evaluated by
44 an independent review model called Auto Review.79 an independent review model called Auto Review.
45* Administrative control: team admins can set Team Rules, Cloud Agent80* Administrative control. Team admins can set Team Rules, Cloud Agent
46 delegation, and template sharing. Network Controls, Team Setup, Action81 delegation, template sharing, and the local execution ceiling. Network
47 Recording, and the organization-wide enable switch are Enterprise only.82 Controls, Team Setup, Allow Local Egress, Action Recording, Enforce
83 Auto-review, Auto-review rules, and the organization-wide enable switch are
84 Enterprise only.
48 85
49The pieces fit together like this:86The pieces fit together like this:
50 87
511. Local machine: chat, review, and approvals happen on the member's device,881. Local machine. Chat, review, and approvals happen on the member's device.
52 and work runs in the hosted computer. Optional89 Work runs in the hosted computer. Optional
53 [local execution](/grok-bot/security#local-execution) requires per-command90 [local execution](/grok-bot/security#local-execution) requires per-command
54 approval by default and can be turned off.91 approval by default and can be turned off.
552. Environment: one persistent Firecracker microVM per user, shared by every922. Environment. One persistent Firecracker microVM per user. Every Bot that
56 Bot that user runs. Admins manage Grok Bot from the Grok Bot page of the93 user runs shares that computer. Admins manage Grok Bot from the Grok Bot
57 [Cursor dashboard](https://cursor.com/dashboard/bot). Team Rules, Cloud94 page of the [Cursor dashboard](https://cursor.com/dashboard/bot). Team
58 Agent delegation, and public template sharing are available to team admins;95 Rules, Cloud Agent delegation, public template sharing, and Execution on
59 the organization-wide enable switch, Network Controls, Team Setup, Action96 Local Computer are available to team admins. Enterprise only on that page:
60 Recording, and computer management for organization admins are Enterprise97 the organization-wide enable switch, Network Controls, Team Setup, Allow
61 only. Members never see this page.98 Local Egress, Action Recording, Enforce Auto-review, Auto-review rules, and
623. The Bot: shell, browser, and computer use inside the hosted computer. A Bot99 computer management for organization admins. Members never see this page.
1003. The Bot. Shell, browser, and computer use inside the hosted computer. A Bot
63 has no access by default and acts only with accounts the member signs it101 has no access by default and acts only with accounts the member signs it
64 into; it hands login, two-factor authentication, and payment steps to the102 into. It hands login, two-factor authentication, and payment steps to the
65 member.103 member.
664. Plugins: your team's Cursor MCP (Model Context Protocol) policy applies in1044. Plugins. Your team's Cursor MCP (Model Context Protocol) policy applies in
67 full, allowing or blocking each connector. OAuth tokens stay on Cursor's105 full, allowing or blocking each connector. OAuth tokens stay on Cursor's
68 connector backend, and Bots invoke tools without receiving them.106 connector backend, and Bots invoke tools without receiving them.
695. Cloud Agents: Grok Bot can delegate coding tasks to separate computers under1075. Cloud Agents. Grok Bot can delegate coding tasks to separate computers under
70 your existing [Cloud Agent](https://cursor.com/docs/cloud-agent) controls.108 your existing [Cloud Agent](https://cursor.com/docs/cloud-agent) controls.
71 Admins can disable spawning.109 Admins can disable spawning.
726. Models and data: Cursor manages model selection. With Privacy Mode enabled,1106. Models and data. Cursor manages model selection. With Privacy Mode enabled,
73 customer data is not used for training; Cursor enforces this on its servers,111 customer data is not used for training; Cursor enforces this on its servers,
74 and when the setting cannot be verified, the system defaults to not training.112 and when the setting cannot be verified, the system defaults to not training.
75 113
86temporary files when work completes. When a workload needs its own computer and124temporary files when work completes. When a workload needs its own computer and
87credential set, give it its own Cursor user.125credential set, give it its own Cursor user.
88 126
89## Roll out Grok Bot127## Admin controls
90 128
91### Before you roll out129Most Grok Bot settings sit on the Grok Bot page of the
130[Cursor dashboard](https://cursor.com/dashboard/bot), which only admins see. A
131few live in Team Settings, your Team Marketplace, or your identity provider.
132Several controls are available only on the Enterprise plan; the rest are
133available on Teams and Enterprise.
92 134
93* Move off Privacy Mode (Legacy). That setting blocks Grok Bot entirely, and135### Access and identity
94 you are prompted to change it before enabling. Check the privacy setting in
95 Team Settings.
96* Plan for shared egress addresses. If your company restricts services by
97 source IP, see [static egress IPs](/grok-bot/security#static-egress-ips).
98* Decide how members sign in to company tools from the computer. See
99 [identity and sign-ins](/grok-bot/security#identity-and-sign-ins) and, for
100 Okta and Microsoft Entra ID steps,
101 [Configure identity and access](/grok-bot/identity-and-access).
102* Review the policies Grok Bot inherits: Team Rules and Auto Review team
103 instructions, which are on Teams and Enterprise. The MCP allowlist is
104 Enterprise only.
105 136
106### Set up your team137Who can use Grok Bot, and how members are provisioned.
107 138
1081. Open [Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot).139#### Enable Grok Bot
109 **Enable Grok Bot** is Enterprise only; **Enable** opens a setup modal that
110 covers privacy mode, pricing, and model availability. Self-serve Teams see
111 **Learn more** and an onboarding path, not an organization-wide switch.
1122. Configure Network Controls (Enterprise only). Teams without a policy default
113 to allow-all, and self-serve Teams do not see this panel. See
114 [network policy](/grok-bot/security#network-policy) for the modes.
1153. Audit your connector policy. Any permitted connector is available to every
116 Bot a member runs; see the **Connector policy** entry under
117 [admin controls](#admin-controls).
1184. Review the delegation and sharing defaults. Check the **Cloud Agents** and
119 **Public template sharing** entries under [admin controls](#admin-controls);
120 both ship with permissive defaults.
121 140
122### Admin controls141The organization-wide switch on the Grok Bot page, with **Manage Group Access**
142beside it. Turning it on opens a setup modal that covers privacy mode, pricing,
143and model availability. Turning it off blocks every member without deleting
144their computers. See
145[Enabling Grok Bot for your team](#enabling-grok-bot-for-your-team).
123 146
124Most Grok Bot settings sit on the Grok Bot page of the147Available on the Enterprise plan.
125[Cursor dashboard](https://cursor.com/dashboard/bot), and that page is148
126admin-only. Enterprise only means the control is hidden on self-serve Teams; it149#### SCIM
127is not a default you can turn on later.150
128 151SCIM 2.0 provisioning and deprovisioning through your identity provider.
129| Control | Availability | Where |152Members sign in to Grok Bot with their Cursor account, so your existing
130| --- | --- | --- |153[SCIM](https://cursor.com/docs/account/teams/scim) and SSO setup carries over.
131| Enable Grok Bot | Enterprise only | Grok Bot page |154For Okta and Entra ID steps, including app assignment and sign-in rules for the
132| Network Controls | Enterprise only | Grok Bot page |155computer browser, see
133| Team Setup | Enterprise only | Grok Bot page |156[Configure identity and access](/grok-bot/identity-and-access).
134| Action Recording | Enterprise only | Grok Bot page |157
135| Computer management | Enterprise only; organization admins | Grok Bot page |158Available on the Enterprise plan.
136| Cloud Agents | Teams and Enterprise | Grok Bot page |159
137| Public template sharing | Teams and Enterprise | Grok Bot page |160### Agent capabilities
138| Team Rules | Teams and Enterprise | Grok Bot page |161
139| Connector policy | Teams and Enterprise; the MCP allowlist is Enterprise only | Teams Marketplace |162What Bots may do on behalf of members. Each control applies to every member's
140| Auto Review team instructions | Teams and Enterprise | Team Settings, Security and Automation |163Bots.
141| Audit logs | Enterprise only | Dashboard audit log, or SIEM stream |164
142| OpenTelemetry Export | Enterprise only | Team Settings |165#### Cloud Agents
143| SCIM | Enterprise only | Identity provider |166
144 167Allows or blocks Bots delegating coding tasks to Cursor Cloud Agents. The
145* **Enable Grok Bot.** Enterprise only. An organization-wide switch. Incomplete168switch is on the Grok Bot page, applies to the whole team, and is on by
146 setup shows **Disabled** and **Enable**; after setup, the page shows169default. Delegated work runs on separate computers under your existing
147 **Enabled** and **Disable**. Disabling blocks members and does not delete170[Cloud Agent](https://cursor.com/docs/cloud-agent) controls. Turn it off when
148 member computers. Self-serve Teams do not get this switch; their dashboard171your team does not need delegation.
149 shows **Learn more**, and a first admin visit can open onboarding at172
150 `/bot/onboarding` in the dashboard.173#### Public template sharing
151* **Network Controls.** Enterprise only. Four modes, directory-group scope, and174
152 a lock. The dashboard label is **Network Controls**. Self-serve Teams have no175Controls whether members can publish Bot templates outside your team. Off
153 destination allowlist. See176keeps sharing team-only, and Cursor enforces the policy on its servers,
154 [network policy](/grok-bot/security#network-policy).177including for templates that are already public. Enterprise teams start with
155* **Team Setup.** Enterprise only. Manifests of admin install scripts that run178public sharing off; other teams start with it allowed. For what a shared
156 on every team computer, so your standard tooling is in place everywhere. Do179template contains, see [Share a Bot](/grok-bot/bots#share-a-bot).
157 not put secret values in setup scripts. To install your own networking client180
158 and reach private services, see181#### Connector policy
159 [Connect to private networks](/grok-bot/private-networks).182
160* **Action Recording.** Enterprise only. Records Bot actions and is off by183Grok Bot inherits your team's Cursor connector policy. There is no separate
161 default. Events do not appear on the Audit Log page. To receive them in your184Grok Bot connector list, and connectors appear as plugins in the app. Set which
162 own collector, configure185servers members can use from your Team Marketplace on the dashboard's
163 [OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export),186[Plugins page](https://cursor.com/dashboard/plugins), not on the Grok Bot page.
164 which is also Enterprise only. See187The MCP allowlist is Enterprise only; see
165 [logging and audit](/grok-bot/security#logging-and-audit).188[MCP server trust management](https://cursor.com/docs/enterprise/model-and-integration-management#mcp-server-trust-management).
166* **Computer management.** Enterprise only. Organization admins can look up any189Any permitted connector is available to every Bot a member runs, and a blocked
167 member's computer, see when it was created and last active, and terminate190one shows as **Disabled by team admin**. Pushing connectors to members, whether
168 it. Team admin rights are not enough, because a computer spans every team191mandatory or default-on, is not available.
169 the member belongs to. The durable disk is kept, and the member's next192
170 session starts a fresh computer.193#### Execution on Local Computer
171* **Cloud Agents.** Teams and Enterprise. Allow or block delegation to Cursor194
172 Cloud Agents. The default is on, and the toggle applies to the whole team.195Caps what Bots may do on a member's own machine through the desktop app: open
173* **Public template sharing.** Teams and Enterprise. Off keeps Bot template196files and run tasks. Pick **Always allow**, **Ask every time**, or **Never
174 sharing within your team, and the policy is enforced on Cursor's servers,197allow** on the Grok Bot page. **Always allow**, the default, leaves the choice
175 including for existing public templates. Enterprise teams start with public198to each member, whose own setting defaults to asking before every task. **Ask
176 sharing off; other teams start with it allowed. The control itself is on199every time** makes every local task ask for approval, and **Never allow** turns
177 both plans.200local execution off for the whole team. A member's own setting still applies
178* **Team Rules.** Teams and Enterprise. Rules applied for every member's Bots.201when it is stricter than the team's. Pick **Never allow** unless Bots have a
179 Rules are always required and cannot be made optional, and you scope each202specific reason to work on member machines. See
180 rule to Cursor, Grok Bot, or both. Keep them short and few, like "never move203[local execution](/grok-bot/security#local-execution).
181 company data to personal accounts"; for enforcement, use Auto Review204
182 instructions instead.205#### Allow Local Egress
183* **Auto Review team instructions.** Teams and Enterprise. Team-wide allow and206
184 block instructions that feed the reviewer's decisions for every member.207Let members route Grok Bot's web traffic through their own computer. Off
185 These live in team settings under Security and Automation, not on the Grok208disables the option in Grok Bot. The switch is on by default. Turning it off
186 Bot page.209stops active routes within five minutes. Turning it back on restores each
187* **Local execution.** The policy for Bots acting on a member's own machine.210member's previous choice. See
188 See [local execution](/grok-bot/security#local-execution). A dashboard211[Route traffic through your desktop](/grok-bot/settings-and-notifications#route-traffic-through-your-desktop).
189 control for the team ceiling is not available on any plan.212
190* **Connector policy.** Grok Bot inherits your team's Cursor connector policy.213Available on the Enterprise plan.
191 There is no separate Grok Bot connector list, and connectors appear as214
192 plugins in the app. Configure marketplace require and restrict in Teams215### Rules and approvals
193 Marketplace (Integrations), not on the Grok Bot page. The MCP allowlist is216
194 Enterprise only; see217Guidance Bots follow, and the review layer that stops actions.
195 [MCP server trust management](https://cursor.com/docs/enterprise/model-and-integration-management#mcp-server-trust-management).218
196 When policy blocks a server, members see the plugin as219#### Team Rules
197 **Disabled by team admin**. Provisioning connectors to members, whether220
198 mandatory or default-on, is not available.221Rules that every member's Bots follow. Add them from the Grok Bot page and
199* **Audit logs.** Enterprise only. Admin, security, and authentication events.222scope each rule to Cursor, Grok Bot, or both. Rules applied to Grok Bot are
200 View them in the dashboard or stream them to your SIEM. Self-serve Teams do223always required, so members cannot turn them off. Keep them short and few, like
201 not get this log.224"never move company data to personal accounts." Rules guide a Bot; for approval
202* **OpenTelemetry Export.** Enterprise only. The customer path for Action225behavior, use [Auto-review rules](#auto-review-rules).
203 Recording events. Configure it under Team Settings; see226
204 [OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export).227#### Enforce Auto-review
205* **SCIM.** Enterprise only. SCIM 2.0 provisioning and deprovisioning. See228
206 [Configure identity and access](/grok-bot/identity-and-access).229Prevents members from turning Auto-review off. The switch is on the Grok Bot
230page and is off by default. When it is on, Bots always check risky actions
231before running them and ask for approval when needed. Turn it on before you
232rely on team Auto-review rules.
233
234Available on the Enterprise plan.
235
236#### Auto-review rules
237
238Team-wide **Ask first** and **Allow automatically** rules that apply to every
239member's Bots on top of their own rules. Add them with **Configure Rules** on
240the Grok Bot page; changes save automatically. Members see the team rules under
241**Settings → General → Auto-review** but cannot edit or delete them, and **Ask
242first** wins when rules conflict. Turning enforcement off stops applying the
243team rules. See
244[approvals and Auto Review](/grok-bot/security#approvals-and-auto-review).
245
246Available on the Enterprise plan.
247
248### Computers and network
249
250How team computers are set up, what they can reach, and how you recreate or
251terminate them.
252
253#### Network Controls
254
255Restricts which destinations team computers can reach. Pick one of four modes,
256from allow-all to a team allowlist of domains and IP ranges. Directory groups
257can carry their own policy, and a lock makes the team policy apply to everyone.
258Teams without a policy default to allow-all. See
259[network policy](/grok-bot/security#network-policy) for the modes and how a
260new policy reaches running computers.
261
262Available on the Enterprise plan.
263
264#### Team Setup
265
266Manifests of install scripts that run on every team computer, so the same
267tooling is present everywhere. Keep secret values out of setup scripts. Members
268see the managed setup under
269[Team Setup](/grok-bot/settings-and-notifications#team-setup) in the app,
270where they can review or reinstall it. For how manifests run, and to install a
271networking client that reaches private services, see
272[Connect to private networks](/grok-bot/private-networks).
273
274Available on the Enterprise plan.
275
276#### Grok Bot Computers
277
278Lets organization admins recreate or terminate the computers of many members
279at once, with a result for each member. Team admin rights are not enough,
280because one computer spans every team the member belongs to. **Recreate** moves
281members to the latest image and Team Setup while keeping their Bots, files, and
282logins. **Terminate** ends the member's current work and keeps the durable
283disk; the member's next session starts a fresh computer on it. Neither action
284removes access: to do that, remove the member from the team or turn off Grok
285Bot for their group, and revoke their sessions in your identity provider. See
286[Manage Grok Bot computers](/grok-bot/computers).
287
288Available on the Enterprise plan.
289
290### Logging and audit
291
292What gets recorded, and where it goes.
293
294#### Action Recording
295
296Records Bot actions: connector (MCP) tool calls, shell commands, browser
297navigations, and computer use sessions. Events are sanitized before they are
298stored or exported. Shell commands are secret-scrubbed; browser navigations
299keep each page as `scheme://host/path` with the title but strip query strings
300and credentials; computer use sessions record action and screenshot counts and
301the session duration, without the screenshots, clicks, or typed text. The
302switch is on the Grok Bot page and is off by default. Recorded events do not
303appear on the Audit Log page. To receive them in your own collector, configure
304[OpenTelemetry Export](#opentelemetry-export), which delivers each event
305tagged `cursor.surface=grok_bot`. Retention details are on
306[logging and audit](/grok-bot/security#logging-and-audit).
307
308Available on the Enterprise plan.
309
310#### Audit logs
311
312Admin, security, and authentication events, plus Grok Bot control-plane
313events: Bot creation, member access changes, Team Setup manifests, MCP
314authentication, Slack account links, and routines. Each row names the
315application that acted, so you can filter the log to Grok Bot. View them on the
316[Audit Log page](https://cursor.com/dashboard/audit-log) or stream them to
317your SIEM; see
318[audit logs](https://cursor.com/docs/enterprise/compliance-and-monitoring#audit-logs).
319For the actions Bots took, use [Action Recording](#action-recording).
320
321Available on the Enterprise plan.
322
323#### OpenTelemetry Export
324
325Streams Cursor usage metrics and logs, including recorded Grok Bot actions, to
326a collector you run. It is the customer path for Action Recording events.
327Configure it under **Team Settings → OpenTelemetry Export**. Endpoint
328requirements and the event schema are on
329[OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export).
330
331Available on the Enterprise plan.
332
333## Admin API
334
335Enable Grok Bot and manage capabilities, Enforce Auto-review, group access,
336network policy, team rules, and setup scripts through the
337[Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot).
207 338
208## Security339## Security
209 340
210The security model, network policy, approvals and Auto Review, identity,341The security model, network policy, approvals and Auto Review, identity,
211logging, data handling, hosting, and certifications live on342logging, data handling, and certifications live on
212[Grok Bot security](/grok-bot/security). Common review questions are on the343[Grok Bot security](/grok-bot/security). Common review questions are on the
213[Grok Bot security FAQ](/grok-bot/security-faq).344[Grok Bot security FAQ](/grok-bot/security-faq).
214 345
218 349
219For administrators:350For administrators:
220 351
2211. Configure Network Controls (Enterprise only). Teams without a policy default3521. Configure Network Controls. Enterprise only. Teams without a policy default
222 to allow-all, and self-serve Teams cannot set this. See353 to allow-all. Self-serve Teams cannot set this. See
223 [network policy](/grok-bot/security#network-policy).354 [network policy](/grok-bot/security#network-policy).
2242. Audit connector policy in Teams Marketplace before enabling Grok Bot. Any3552. Audit connector policy in Teams Marketplace before enabling Grok Bot. Any
225 permitted connector is available to every Bot a member runs.356 permitted connector is available to every Bot a member runs.
2263. Ask members to keep Auto Review enforcement on. Enforcement is enabled by3573. Turn on Enforce Auto-review before you rely on team rules. Enterprise only.
227 Cursor and currently active for all users, and each member's own setting358 Members can add stricter personal rules on top, and **Ask first** wins when
228 remains the off switch.359 rules conflict.
2294. Set an explicit local execution policy, and decide whether Bots may act on3604. Set Execution on Local Computer to **Never allow** unless Bots need to act
230 member machines at all.361 on member machines. The default leaves the choice to each member.
2315. Disable Cloud Agent spawning if you do not need delegation.3625. Disable Cloud Agent spawning if you do not need delegation.
2326. Keep public template sharing off unless members should publish Bot3636. Keep public template sharing off unless members should publish Bot
233 templates outside the team.364 templates outside the team.
2347. Add team block instructions for actions that are never acceptable in your3657. Add team Auto-review rules. Enterprise only. Cover actions that should
235 environment, and allow instructions for routine safe work. Production366 always ask first or can proceed automatically. Production deployments,
236 deployments, external email, payments, and accepting legal terms are common367 external email, payments, and accepting legal terms are good **Ask first**
237 block examples.368 examples. Keep automatic rules narrow.
2388. Gate sign-in to managed devices through your identity provider. Grok Bot3698. Gate sign-in to managed devices through your identity provider. Grok Bot
239 sign-in uses your SSO, so a device-aware sign-in policy applies to it. This370 sign-in uses your SSO, so a device-aware sign-in policy applies to it. This
240 gates sign-in, not the hosted computer itself.371 gates sign-in, not the hosted computer itself.
258### Can I turn Grok Bot on or off for my team?389### Can I turn Grok Bot on or off for my team?
259 390
260The organization-wide **Enable Grok Bot** switch is Enterprise only. It lives391The organization-wide **Enable Grok Bot** switch is Enterprise only. It lives
261on the Grok Bot page of the Cursor dashboard, and self-serve Teams do not get392on the Grok Bot page of the Cursor dashboard. Self-serve Teams do not get this
262it. Disabling blocks members without deleting their computers.393switch. Disabling blocks members without deleting their computers.
394
395### Can I manage Grok Bot through the Admin API?
396
397Yes. Use the
398[Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot).
263 399
264### Can I set a Grok Bot spend cap?400### Can I set a Grok Bot spend cap?
265 401
280### How do members request access?416### How do members request access?
281 417
282Members can send a request from the app. On a pooled Enterprise team whose418Members can send a request from the app. On a pooled Enterprise team whose
283admin has not finished setup, members see a team-setup message instead; the419admin has not finished setup, members see a team-setup message instead. The
284next step is for an admin to use the Enterprise-only enable switch. Self-serve420next step is for an admin to use the Enterprise only enable switch. Self-serve
285Teams do not use that switch.421Teams do not use that switch.
286 422
423### Can I see what kind of work my team does with Grok Bot?
424
425Yes, on Enterprise teams where it has rolled out. The Conversation Insights
426page of the Analytics dashboard has a Grok Bot source that groups Bot
427conversations by Type of Work and Level of Automation. See
428[Grok Bot Conversation Insights](https://cursor.com/docs/account/teams/analytics#grok-bot-conversation-insights).
429
287Isolation, egress, approvals, logging, and data-handling questions are on the430Isolation, egress, approvals, logging, and data-handling questions are on the
288[Grok Bot security FAQ](/grok-bot/security-faq).431[Grok Bot security FAQ](/grok-bot/security-faq).
289 432
293* [Grok Bot security FAQ](/grok-bot/security-faq)436* [Grok Bot security FAQ](/grok-bot/security-faq)
294* [Configure identity and access](/grok-bot/identity-and-access)437* [Configure identity and access](/grok-bot/identity-and-access)
295* [Connect to private networks](/grok-bot/private-networks)438* [Connect to private networks](/grok-bot/private-networks)
439* [Configure TLS-inspecting proxies](/grok-bot/proxies)
440* [Manage Grok Bot computers](/grok-bot/computers)
296* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)441* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)
442* [Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot)
443* [Grok Bot Conversation Insights](https://cursor.com/docs/account/teams/analytics#grok-bot-conversation-insights)
297* [Plans and billing](https://cursor.com/help/grok-bot/plans)444* [Plans and billing](https://cursor.com/help/grok-bot/plans)
298* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)445* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)
299 446