SpyBara
Go Premium

Documentation 2026-09-11 21:00 UTC to 2026-09-16 19:01 UTC

10 files changed +809 −271. View all changes and history on the product overview
2026
Tue 22 23:58 Mon 21 23:00 Sat 19 23:59 Fri 18 23:59 Wed 16 19:01 Fri 11 21:00 Mon 7 22:57
Details

42 42 

43## Configure Auto Review43## Configure Auto Review

44 44 

45When Auto Review enforcement is available, Grok Bot evaluates tool calls and45With Auto Review on, Grok Bot evaluates tool calls and computer actions before

46computer actions before they run. Open **Settings → General → Auto-review** to46they run. Open **Settings → General → Auto-review** to add rules.

47add rules.

48 47 

49* **Require Approval** rules always stop matching actions for you.48* **Ask first** rules always stop matching actions for you.

50* **Always Allow** rules let matching actions proceed only when the automated49* **Allow automatically** rules let matching actions proceed only when the

51 review does not identify another reason to stop.50 automated review does not identify another reason to stop.

52* If both kinds of rule match, **Require Approval** wins.51* If both kinds of rule match, **Ask first** wins.

52 

53If your team admin enforces Auto Review, the same table also shows locked team

54rules that you cannot edit or delete. Your own rules apply on top and can only

55make behavior stricter. See

56[Auto-review rules](/grok-bot/teams-and-enterprises#auto-review-rules).

53 57 

54Write narrow rules around a known action and scope:58Write narrow rules around a known action and scope:

55 59 

56* Require approval before sending any external email.60* Ask first before sending any external email.

57* Require approval before changing a production dashboard.61* Ask first before changing a production dashboard.

58* Always allow running `git status` in `/workspace/reports`.62* Allow automatically when running `git status` in `/workspace/reports`.

59 63 

60Avoid broad rules such as “allow everything in the browser.” Websites and tool64Avoid broad rules such as “allow everything in the browser.” Websites and tool

61behavior change over time. Auto Review is model-based and should complement,65behavior change over time. Auto Review is model-based and should complement,


93* Are never allowed97* Are never allowed

94 98 

95The default is **Ask every time**. Use **Never allowed** unless a Bot has a99The default is **Ask every time**. Use **Never allowed** unless a Bot has a

96specific reason to work on your local files. These settings do not prevent the100specific reason to work on your local files. Your team admin can cap this

97Bot from using its cloud computer.101setting for the whole team; when the team's policy is stricter than yours, the

102team's applies. These settings do not prevent the Bot from using its cloud

103computer.

98 104 

99## Understand the shared-computer boundary105## Understand the shared-computer boundary

100 106 

computers.md +104 −0 created

Details

1#### Manage and protect

2 

3# Manage Grok Bot computers

4 

5Each member of your team gets one hosted computer where every Bot they run does

6its work. **Grok Bot Computers** on the

7[Grok Bot page of the Cursor dashboard](https://cursor.com/dashboard/bot) lets

8an organization admin recreate or terminate those computers for many members at

9once, with a confirmation step and a result for each member. For the rest of

10the admin controls, see

11[Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises).

12 

13Grok Bot Computers is Enterprise only, and it appears only for organization

14admins. Team admin rights are not enough, because one computer spans every team

15the member belongs to. Members never see this control.

16 

17## Recreate or terminate

18 

19Both actions keep the member's durable disk. They differ in what happens next.

20 

21| Action | What happens | What members keep | When to use it |

22| --- | --- | --- | --- |

23| **Recreate** | Builds a replacement computer on the latest image and runs [Team Setup](/grok-bot/teams-and-enterprises#team-setup). The current computer stays available until the replacement is ready, then Grok Bot switches over. | Synced Bots, files, and logins. A Bot that is mid-turn is asked to pause at a safe point and resumes on the new computer. If it cannot pause in time, the recreate for that member is not started and shows as failed. | Roll out a new image or apply an updated Team Setup manifest to many members at once. [Network policy](/grok-bot/security#network-policy) changes reach computers without a recreate. |

24| **Terminate** | Deletes the member's computer, running or hibernated. It does not restart on its own; the member's next session starts a fresh computer on the same durable disk. | Synced Bots, files, and logins. Running work stops. | End a member's current work, or clear a computer that is stuck. Terminating does not remove access; see the [FAQ](#faq). |

25 

26Both actions remove apps and packages that members installed themselves.

27Anything your Team Setup manifests install comes back on the new computer.

28 

29## Run an operation

30 

311. Open Grok Bot Computers. Go to

32 [Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot), find

33 **Grok Bot Computers**, and select **Manage**.

342. Select members. Search by name or email, then check the members you want.

35 **Select all** picks everyone in the current results.

363. Choose an action. Select **Recreate VMs…** or **Terminate VMs…**. A

37 confirmation screen restates the action and the number of members it

38 affects.

394. Confirm. Select **Recreate VMs** or **Terminate VMs** to start. Members

40 without a computer are skipped.

415. Watch the results. A progress card shows queued, running, complete, skipped,

42 and failed counts, and each member's row shows its status. When the

43 operation finishes, select **Done** to clear the results and start another.

44 

45## How an operation runs

46 

47* **It runs on Cursor's side.** Closing the dialog or the browser does not stop

48 it. Reopen **Manage** in the same browser to pick the progress back up.

49* **Large operations take a while.** Members are processed in batches, and each

50 recreate waits for the replacement computer to be ready before it counts as

51 complete.

52* **One operation per team at a time.** The action buttons stay disabled until

53 you select **Done** on the finished results.

54* **Retry Start never duplicates work.** Use it when the dashboard cannot

55 confirm the operation started.

56 

57## Skipped and failed members

58 

59A finished operation lists a result for every member you selected.

60 

61| Result | Meaning | What to do |

62| --- | --- | --- |

63| **Skipped**, No VM | The member had no running or hibernated computer. | Nothing. |

64| **Skipped**, Action could not be completed | The member left the team, or their account changed, while the operation was queued. | Nothing. |

65| **Failed**, Another recreation is in progress | The member's computer is already being recreated, by an update or another admin. | Wait for it to finish, then run again for this member. |

66| **Failed**, VM scan incomplete | Cursor could not confirm the state of the member's computer, so it made no change. | Run the operation again in a few minutes. |

67| **Failed**, Action could not be completed | The recreate or terminate did not finish. For a recreate, a Bot on the member's computer may have been unable to pause in time; the member's current computer is left as it was. | Run the operation again for the affected members, once their Bots are idle if you can. If it fails twice, [contact support](https://cursor.com/help/grok-bot/get-help) with the member's email and the time of the operation. |

68 

69## What members see

70 

71During a recreate, the desktop app shows **Updating Grok Bot's Computer** until

72the switch completes. Bots that were working pause at a safe point and continue

73on the new computer. If a Bot cannot pause in time, the member keeps their

74current computer and that member's result shows as failed. Sign-in sessions

75inside the computer can drop when it is recreated, so members sign in to

76company tools again under your identity provider's policies.

77 

78After a terminate, the member's next message starts a fresh computer on their

79durable disk. The reconnect can take a few minutes. Bots, files, and logins

80that had synced come back; a turn that was running is lost.

81 

82## FAQ

83 

84### Can I recreate a member's computer from a different team?

85 

86Yes. Select the member from any team they belong to. One computer serves every

87team the member is in, so recreating or terminating it from one team affects

88the same computer everywhere.

89 

90### Does terminating stop a member from using Grok Bot?

91 

92No. Terminating a computer ends the member's current work; their next message

93starts a fresh computer on the same durable disk, with their Bots, files, and

94logins. To remove access, remove the member from the team or turn off their

95access with **Manage Group Access**, and revoke their sessions in your identity

96provider. See

97[Enable Grok Bot](/grok-bot/teams-and-enterprises#enable-grok-bot).

98 

99## Related pages

100 

101* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)

102* [Grok Bot security](/grok-bot/security)

103* [Connect to private networks](/grok-bot/private-networks)

104* [Update, recover, or reset the computer](/grok-bot/computer-and-apps#update-recover-or-reset-the-computer)

Details

112* Password plus a second factor that works in a remote browser, such as Okta112* Password plus a second factor that works in a remote browser, such as Okta

113 Verify push or an authenticator app.113 Verify push or an authenticator app.

114* Passkeys stored in a password manager on the computer, installed with a114* Passkeys stored in a password manager on the computer, installed with a

115 [Team Setup script](/grok-bot/teams-and-enterprises#admin-controls).115 [Team Setup script](/grok-bot/teams-and-enterprises#team-setup). Team Setup

116 is Enterprise only.

116 117 

117> Requiring managed devices for Grok Bot sign-in itself still works. Grok Bot118> Requiring managed devices for Grok Bot sign-in itself still works. Grok Bot

118> uses your Cursor SSO, so a device-aware sign-in policy in your identity119> uses your Cursor SSO, so a device-aware sign-in policy in your identity

Details

5Grok Bot computers run in Cursor's cloud and reach the internet through5Grok Bot computers run in Cursor's cloud and reach the internet through

6[shared static egress IP addresses](/grok-bot/security#static-egress-ips).6[shared static egress IP addresses](/grok-bot/security#static-egress-ips).

7If the systems your Bots need, such as internal APIs, source control, databases,7If the systems your Bots need, such as internal APIs, source control, databases,

8or staging environments, live on a private network, you can connect by8or staging environments, live on a private network, route traffic through a

9installing your organization's networking client on every team computer through9member's desktop or install your organization's networking client on every team

10**Team Setup**. Tailscale and Cloudflare Tunnel are common choices, and this10computer through **Team Setup**. Tailscale and Cloudflare Tunnel are common

11page has a worked example for each. Other VPN, zero-trust, or mesh clients that11client choices, and this page has a worked example for each. Other VPN,

12run on Linux follow the same pattern. Your services stay off the public12zero-trust, or mesh clients that run on Linux follow the same pattern. Your

13internet, and access is governed by the access controls and identity provider13services stay off the public internet, and access is governed by the access

14you already use.14controls and identity provider you already use.

15 15 

16> Team Setup is available on the Enterprise plan. The Grok Bot16> Team Setup is Enterprise only. It does not appear on other plans. Network

17> Controls is also Enterprise only. That

17> [network policy](/grok-bot/security#network-policy) is a separate layer that18> [network policy](/grok-bot/security#network-policy) is a separate layer that

18> still applies; private network reach does not replace your destination19> still applies; private network reach does not replace your destination

19> allowlist.20> allowlist.

20 21 

21## What you can do22## What you can do

22 23 

24* Route one member's traffic through their desktop, so Bots can reach services

25 available from that device and destinations see its IP address.

23* Install your networking client on every team computer automatically, from one26* Install your networking client on every team computer automatically, from one

24 admin-managed manifest, with no per-computer setup.27 admin-managed manifest, with no per-computer setup.

25* Let Bots reach services on your private network without exposing those28* Let Bots reach services on your private network without exposing those


27* Keep control on your side: your network, your access rules, and your identity30* Keep control on your side: your network, your access rules, and your identity

28 provider. You can revoke a computer from your own admin console at any time.31 provider. You can revoke a computer from your own admin console at any time.

29 32 

30## A pattern you operate33## Choose a connection method

34 

35| Method | Use it when |

36| --- | --- |

37| Route egress through a desktop | One member needs access through a network already available from their device |

38| Install a networking client with Team Setup | Your Enterprise team needs a consistent connection on every hosted computer |

39 

40### Route through a member's desktop

41 

42In the Grok Bot desktop app, open **Settings → Computer** and turn on **Route

43egress through this desktop**. The route uses the current device's network and

44IP address. It stops when the setting is turned off or an Enterprise admin

45disables **Allow Local Egress**.

46 

47Each member controls their own desktop route. Enterprise admins can remove this

48option for the whole team from

49[Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot). See

50[Route traffic through your desktop](/grok-bot/settings-and-notifications#route-traffic-through-your-desktop).

51 

52### Install a networking client with Team Setup

31 53 

32This is a pattern you run, not a Cursor-managed network mode. Cursor provides54This is a pattern you run, not a Cursor-managed network mode. Cursor provides

33the hook: Team Setup runs your install scripts on every team computer. You own55the hook: Team Setup runs your install scripts on every team computer. You own


149 manual, since scripts cannot hold secrets. Check the machine list in your171 manual, since scripts cannot hold secrets. Check the machine list in your

150 Tailscale admin console.172 Tailscale admin console.

151* Your team's network policy is allowlist-only and blocks Tailscale's173* Your team's network policy is allowlist-only and blocks Tailscale's

152 coordination servers or relays. Allow the endpoints from Tailscale's docs,174 coordination servers or relays. Allow the endpoints from Tailscale's docs.

153 then recreate the computer.175 Running computers apply the change within about a minute. Sleeping computers

176 apply it when they next wake.

154* The exit node is not advertised or approved in your tailnet. Check route177* The exit node is not advertised or approved in your tailnet. Check route

155 settings in the admin console.178 settings in the admin console.

156* The computer was recreated, for example after an image update or reset, and179* The computer was recreated, for example after an image update or reset, and


196* Cloudflare Access denies the request. Check your Access logs and confirm the219* Cloudflare Access denies the request. Check your Access logs and confirm the

197 member has authenticated.220 member has authenticated.

198* Your team's network policy is allowlist-only and blocks the tunnel hostname or221* Your team's network policy is allowlist-only and blocks the tunnel hostname or

199 Cloudflare's endpoints. Allow them, then recreate the computer.222 Cloudflare's endpoints. Allow them. Running computers apply the change within

223 about a minute. Sleeping computers apply it when they next wake.

200* A service token was embedded in the setup script. Do not do this; manifests are224* A service token was embedded in the setup script. Do not do this; manifests are

201 plain text. Use identity-based Access, or supply tokens at use time.225 plain text. Use identity-based Access, or supply tokens at use time.

202* A `cloudflared access tcp` listener is not running when the Bot needs it.226* A `cloudflared access tcp` listener is not running when the Bot needs it.


213 237 

214## Roll out to existing computers238## Roll out to existing computers

215 239 

216* New computers apply manifests when they are created.240* New computers apply manifests when they start.

217* Running computers pick up manifest changes on a periodic refresh; expect up to241* Running computers pick up manifest changes on a periodic refresh, roughly

218 about a day.242 daily.

219* To apply a change immediately, restart or recreate the computer. Members can243* To apply a manifest change immediately, recreate the computer or have the

220 reset their own computer from the desktop app, and organization admins can244 member reset it from the desktop app. Organization admins can recreate or

221 terminate a member's computer from the dashboard. The durable disk is kept,245 terminate a member's computer from the dashboard. The durable disk is kept,

222 and the next session starts a fresh computer that applies current manifests246 and the next computer applies current manifests when it starts.

223 at boot.

224* Image updates recreate computers automatically, and your scripts re-apply.247* Image updates recreate computers automatically, and your scripts re-apply.

225 Sign-in sessions, including your network client's login, may need to be248 Sign-in sessions, including your network client's login, may need to be

226 re-established after a computer is recreated.249 re-established after a computer is recreated.


231layer that controls which destinations team computers may reach.254layer that controls which destinations team computers may reach.

232If your team uses **Team allowlist only**, add the destinations your networking255If your team uses **Team allowlist only**, add the destinations your networking

233client needs, such as coordination servers, relays, and gateways, from your256client needs, such as coordination servers, relays, and gateways, from your

234vendor's documentation. Network policy changes apply when a computer is created257vendor's documentation. Running computers apply policy changes within about a

235or recreated.258minute. Sleeping computers apply them when they next wake. You do not need to

259recreate the computer.

236 260 

237## Limitations261## Limitations

238 262 


269 293 

270### Do existing computers get a new manifest?294### Do existing computers get a new manifest?

271 295 

272Yes, within about a day. Running computers refresh manifests periodically.296Yes. Running computers refresh manifests periodically, roughly daily. To apply

273Restart or recreate a computer to apply changes immediately.297a manifest change immediately, recreate the computer or have the member reset

298it from the desktop app.

274 299 

275### Does this change the IP addresses my services see?300### Does this change the IP addresses my services see?

276 301 


282### We use a strict network allowlist. Will our client work?307### We use a strict network allowlist. Will our client work?

283 308 

284Only if you allow its endpoints. Add the destinations your client requires to309Only if you allow its endpoints. Add the destinations your client requires to

285your team allowlist, then recreate computers to pick up the policy change.310your team allowlist. Running computers apply the change within about a minute.

311Sleeping computers apply it when they next wake.

286 312 

287### Is this the same as the Tailscale and Cloudflare Tunnel sections in the Cloud Agents docs?313### Is this the same as the Tailscale and Cloudflare Tunnel sections in the Cloud Agents docs?

288 314 


292 318 

293### Which plans include Team Setup?319### Which plans include Team Setup?

294 320 

295Enterprise. Team admins manage manifests. If you do not see Team Setup on the321Team Setup is Enterprise only. Team admins manage manifests. If you do not see

296Grok Bot page of the dashboard, contact your account team.322it on the Grok Bot page of the dashboard, you are not on Enterprise, or you

323need your account team to enable Grok Bot for the organization.

297 324 

298### What happens if the setup script fails on some computers?325### What happens if the setup script fails on some computers?

299 326 


306* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)333* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)

307* [Grok Bot security](/grok-bot/security)334* [Grok Bot security](/grok-bot/security)

308* [Configure identity and access](/grok-bot/identity-and-access)335* [Configure identity and access](/grok-bot/identity-and-access)

336* [Configure TLS-inspecting proxies](/grok-bot/proxies), for the path from

337 member devices to Cursor

309* [Cloud Agents: Running Tailscale](https://cursor.com/docs/cloud-agent/setup#running-tailscale)338* [Cloud Agents: Running Tailscale](https://cursor.com/docs/cloud-agent/setup#running-tailscale)

310 and [Running Cloudflare Tunnel](https://cursor.com/docs/cloud-agent/setup#running-cloudflare-tunnel)339 and [Running Cloudflare Tunnel](https://cursor.com/docs/cloud-agent/setup#running-cloudflare-tunnel)

proxies.md +191 −0 created

Details

1#### Manage and protect

2 

3# Configure TLS-inspecting proxies

4 

5The Grok Bot desktop app connects from each member's device to two places:

6Cursor's API at `*.cursor.sh` for chat, sign-in, and approvals, and the

7member's hosted computer at a nested `*.*.cursorvm.com` hostname for computer

8setup, screen, and shell. Secure web gateways that inspect TLS often let the

9first through and break the second. The desktop app then hangs or errors during

10computer setup; in some setups chat keeps working while the computer never

11connects. Zscaler is the most common example, and this page uses it for

12specifics; the same steps apply to any gateway that re-signs TLS or buffers

13responses. This page is for the IT team that runs your gateway. The shared

14domain list and streaming tests live on

15[Enterprise network configuration](https://cursor.com/docs/enterprise/network-configuration);

16this page covers what Grok Bot adds.

17 

18This page is about the path from a member's device to Cursor. It does not

19change where the hosted computer itself may connect; that is the

20[network policy](/grok-bot/security#network-policy). Reaching services on your

21private network from the computer is covered in

22[Connect to private networks](/grok-bot/private-networks).

23 

24## Symptoms

25 

26* **Computer setup hangs or fails.** The app never finishes connecting to the

27 computer. Chat may keep working, since it can reach `api2.cursor.sh`, or

28 stall along with it; either way, the computer link needs `cursorvm.com`.

29* **It works on a hotspot or a personal device** and fails on the corporate

30 network or with the gateway client running.

31* **It works in the office and fails at home.** The exceptions were applied to

32 the office location only. See

33 [apply to every profile](#apply-to-every-profile-including-off-network).

34* **Sign-in or chat stall too.** TLS inspection or response buffering is still

35 active on `cursor.sh`.

36 

37## Allow these domain patterns

38 

39Allow all of these on the gateway and in any DNS filtering. Prefer the

40wildcards over enumerating hostnames; computer hostnames are generated per

41computer.

42 

43| Pattern | Used for |

44| --- | --- |

45| `*.cursor.sh` | Chat, sign-in, approvals, and the rest of the Cursor API |

46| `*.cursor-cdn.com` | Static assets |

47| `*.cursorapi.com` | Extension marketplace and related APIs |

48| `*.cursorvm.com` | The hosted computer and its control plane |

49| `*.*.cursorvm.com` | The same, one level deeper. Required. |

50| `cursor.com`, `downloads.cursor.com` | Installing and updating the desktop app |

51 

52Add both `cursorvm.com` patterns. Computer hostnames have two labels below

53`cursorvm.com`, in the form `<computer>.<cluster>.cursorvm.com`, and a

54single-level wildcard matches only one. A gateway configured with

55`*.cursorvm.com` alone looks correct and still leaves the computer unreachable.

56This is the usual cause of computer setup failing on a network where

57`cursor.sh` is already allowed.

58 

59## Exempt the same domains from TLS inspection and buffering

60 

61Allowing the traffic is not enough. On every domain above:

62 

63* **Bypass TLS (SSL) inspection.** When the gateway re-signs the connection

64 with its own certificate, the computer setup handshake fails even though the

65 hostname is allowed. Cursor's connections are already encrypted end to end.

66* **Turn off response buffering.** Chat and the computer link stream. A gateway

67 that holds responses until they complete leaves the app waiting on output

68 that never arrives.

69 

70If your policy requires inspecting all traffic, the gateway must meet the

71requirements under

72[SSL inspection and DLP](https://cursor.com/docs/enterprise/network-configuration#ssl-inspection-and-dlp):

73HTTP/2 or Cursor's HTTP/1.1 fallback, Server-Sent Events passthrough without

74buffering, and long-lived connections without forced timeouts.

75 

76## Apply to every profile, including off-network

77 

78Zscaler Client Connector keeps running when a device leaves the office, and it

79applies an off-network profile of its own. Exceptions added to the office

80location or to a single policy do not follow the device home. Apply the allow

81rules, the TLS inspection exemption, and any DNS exception to every location,

82profile, and policy group that Grok Bot members fall under, including roaming

83and off-network. Other gateways with separate on- and off-network policies need

84the same treatment.

85 

86The tell: Grok Bot works from the office and fails from home on the same

87laptop, with the gateway client still running.

88 

89## Verify from a member's device

90 

91Run these on a member's device with the gateway client running, after IT has

92applied the changes.

93 

94### Check who issues the certificate

95 

96```bash

97curl -v https://api2.cursor.sh |& grep -C1 issuer:

98```

99 

100The issuer should be **Amazon RSA**. If it names Zscaler or your gateway

101vendor, TLS inspection is still active on `cursor.sh` for this device's

102profile.

103 

104### Check that computer hostnames resolve

105 

106```bash

107nslookup test.us9.cursorvm.com

108```

109 

110You should get addresses back. If the lookup fails, try

111`nslookup test.us9.cursorvm.com 1.1.1.1`. If the public resolver answers and

112your default one does not, the block is the device's DNS or gateway profile,

113and the nested `*.*.cursorvm.com` exception is missing there.

114 

115### Test streaming

116 

117Run the HTTP/1.1 and HTTP/2 streaming tests under

118[Testing proxy connectivity](https://cursor.com/docs/enterprise/network-configuration#testing-proxy-connectivity).

119Output should arrive line by line, not all at once.

120 

121### Retry in the app

122 

123Open the Grok Bot desktop app on the same device and connect to the computer.

124If it still fails, repeat the checks from that device; a passing hotspot and a

125failing corporate network confirms the network is the cause.

126 

127## Scope

128 

129Three controls are easy to confuse:

130 

131| You want to | Use |

132| --- | --- |

133| Let member devices reach Cursor and their hosted computer through your gateway | This page |

134| Limit which destinations the hosted computer may reach | [Network policy](/grok-bot/security#network-policy), Enterprise only |

135| Route hosted computer traffic through a member device | [Route traffic through your desktop](/grok-bot/settings-and-notifications#route-traffic-through-your-desktop) |

136| Install a networking client on every hosted computer | [Team Setup](/grok-bot/private-networks#install-a-networking-client-with-team-setup), Enterprise only |

137 

138By default, the hosted computer's own traffic leaves from Cursor's

139[shared static egress IPs](/grok-bot/security#static-egress-ips) and does not

140pass through the gateway on member devices. When a member enables **Route

141egress through this desktop**, routed traffic uses that device's network and is

142subject to its gateway policy.

143 

144## FAQ

145 

146### We allowlisted \*.cursorvm.com. Why does computer setup still fail?

147 

148Two usual reasons. The nested `*.*.cursorvm.com` pattern is missing, so the

149computer's hostname does not match. Or the domain is allowed but still

150TLS-inspected, so the gateway's certificate breaks the setup handshake. Add the

151nested pattern, exempt both patterns from inspection, then run the

152[checks](#verify-from-a-members-device).

153 

154### We allowed cursor.sh. Why does that not cover the computer?

155 

156They use different hostnames. Chat, sign-in, and approvals go to

157`api2.cursor.sh`, which most gateways already allow. The computer link goes to

158a nested `cursorvm.com` hostname that needs its own allow rule and inspection

159exemption. That is also why chat can keep working on some networks while the

160computer never connects.

161 

162### It works in the office but not from home. What is different?

163 

164The gateway client is still running at home, with an off-network profile that

165did not get the exceptions. Apply them to the roaming and off-network profiles

166too.

167 

168### Our policy requires TLS inspection on all traffic.

169 

170Then the gateway has to pass streaming through untouched. The requirements are

171under

172[SSL inspection and DLP](https://cursor.com/docs/enterprise/network-configuration#ssl-inspection-and-dlp).

173Exempting Cursor's domains is the reliable path; Cursor's connections are

174encrypted end to end already.

175 

176### Does this list also cover the Cursor editor?

177 

178Yes. It is the same list as

179[Enterprise network configuration](https://cursor.com/docs/enterprise/network-configuration#ip-allowlisting).

180The editor's chat and Tab features work without the `cursorvm.com` patterns,

181which is why a gateway that is fine for the editor can still break Grok Bot.

182 

183## Related pages

184 

185* [Enterprise network configuration](https://cursor.com/docs/enterprise/network-configuration)

186* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)

187* [Grok Bot security](/grok-bot/security)

188* [Connect to private networks](/grok-bot/private-networks)

189* [Network, proxy, and remote connections](https://cursor.com/help/troubleshooting/network)

190 

191Contact your Cursor account team for help with your gateway configuration.

security.md +64 −47

Details

10[Grok Bot security FAQ](/grok-bot/security-faq).10[Grok Bot security FAQ](/grok-bot/security-faq).

11 11 

12> Enterprise only on the Grok Bot dashboard: the organization-wide enable12> Enterprise only on the Grok Bot dashboard: the organization-wide enable

13> switch, Network Controls, Team Setup, Action Recording, and computer13> switch, Network Controls, Team Setup, Action Recording, Allow Local Egress,

14> management for organization admins. Audit logs, OpenTelemetry Export, the MCP14> Enforce Auto-review with its team rules, and computer management for

15> allowlist, and SCIM are also Enterprise only. Self-serve Teams do not see15> organization admins. Audit logs, OpenTelemetry Export, the MCP allowlist, and

16> those settings. The full list is under16> SCIM are also Enterprise only. Self-serve Teams do not see those settings.

17> The full list is under

17> [admin controls](/grok-bot/teams-and-enterprises#admin-controls).18> [admin controls](/grok-bot/teams-and-enterprises#admin-controls).

18 19 

19## Network policy20## Network policy


36* Directory groups are Enterprise only, inside Network Controls. Groups can set37* Directory groups are Enterprise only, inside Network Controls. Groups can set

37 their own network policy, which replaces the team's for their members, and a38 their own network policy, which replaces the team's for their members, and a

38 lock makes the team policy effective for everyone.39 lock makes the team policy effective for everyone.

39* The policy is separate from Cloud Agent network settings, and it is applied40* The policy is separate from Cloud Agent network settings. Running computers

40 when a computer is created or recreated. Recreate or restart a running41 apply changes automatically within about a minute. Sleeping computers apply

41 computer to pick up a new policy.42 changes when they next wake. You do not need to recreate the computer.

42* Restricting egress limits where data can be sent. Dedicated data loss43* Restricting egress limits where data can be sent. Dedicated data loss

43 prevention hooks are not available.44 prevention hooks are not available.

44 45 


48 49 

49## Static egress IPs50## Static egress IPs

50 51 

51Hosted computers reach the internet through shared static egress IP addresses.52Hosted computers reach the internet through shared static egress IP addresses

52The ranges are shared across Grok Bot customers, and dedicated per-customer IPs53by default. The ranges are shared across Grok Bot customers, and dedicated per-customer IPs

53are not available, so treat the ranges as identifying Grok Bot traffic rather54are not available, so treat the ranges as identifying Grok Bot traffic rather

54than your team alone. Current ranges are available from your account team, and55than your team alone. Current ranges are available from your account team, and

55the product control is the destination allowlist rather than a source IP56the product control is the destination allowlist rather than a source IP

56editor.57editor.

57 58 

58If your company inspects TLS traffic, allow Cursor's published hostnames and59If member devices sit behind Zscaler or another TLS-inspecting gateway, allow

59bypass inspection for them; your account team can provide the current list.60Cursor's domains and exempt them from inspection on every profile, including

61off-network. See [Configure TLS-inspecting proxies](/grok-bot/proxies).

60 62 

61Team Setup is Enterprise only. Those teams can install their own networking63Members can route traffic through their desktop to use its network and IP

62client on every team computer to reach private services, a path that is64address. Team Setup is Enterprise only. Those teams can also install their own

63separate from these shared egress ranges. See65networking client on every team computer. Both paths are separate from the

66shared egress ranges. See

64[Connect to private networks](/grok-bot/private-networks).67[Connect to private networks](/grok-bot/private-networks).

65 68 

66## Approvals and Auto Review69## Approvals and Auto Review


86and event triggers), and delegation such as Cloud Agent and subagent launches.89and event triggers), and delegation such as Cloud Agent and subagent launches.

87It can let an action proceed, require approval, or deny it.90It can let an action proceed, require approval, or deny it.

88 91 

89* Enforcement is enabled by Cursor and is currently active for all users. Each92* Team admins can enforce Auto-review. Enterprise only. The switch lives on

90 member's own Auto Review setting remains the off switch; for93 the Grok Bot page of the Cursor dashboard. When it is on, members cannot

91 security-sensitive deployments, ask members to leave it on. An94 turn Auto-review off. See

92 organization-level lock is not available.95 [Enforce Auto-review](/grok-bot/teams-and-enterprises#enforce-auto-review).

93* Team instructions shape it for everyone. Admins add team-wide block96* Admins can add team Auto-review rules. Enterprise only. These live on the

94 instructions for actions that are never acceptable and allow instructions97 Grok Bot page too. They apply to every member's Bots, show up as locked rows

95 for routine safe work, in team settings under Security and Automation. Those98 in the member settings table, and save automatically when an admin adds,

96 instructions are not on the Grok Bot page.99 edits, or deletes a rule. If admins turn enforcement off, the team rules stop

100 applying and members go back to their own rules only. See

101 [Auto-review rules](/grok-bot/teams-and-enterprises#auto-review-rules).

97* Members can add personal rules under **Settings → General → Auto-review**.102* Members can add personal rules under **Settings → General → Auto-review**.

98 **Require Approval** rules always stop matching actions, **Always Allow**103 **Ask first** rules always stop matching actions, and **Allow

99 rules let matching actions proceed only when the review finds no other104 automatically** rules let matching actions proceed only when the reviewer

100 reason to stop, and **Require Approval** wins when both match. Narrow rules105 finds no other reason to stop. Personal rules sit on top of team rules but

101 around a known action and scope work best, like "require approval before106 only make behavior stricter; **Ask first** wins when rules conflict. Narrow

102 sending any external email" or "always allow running `git status` in107 rules around a known action and scope work best, like "ask first before

103 `/workspace/reports`"; avoid broad rules like "allow everything in the108 sending any external email" or "allow automatically when running

104 browser". Personal rules are stored on the current desktop and synced to its109 `git status` in `/workspace/reports`"; avoid broad rules like "allow

105 Grok Bot computer, so another desktop installation needs its own.110 everything in the browser". Personal rules are stored on the current desktop

111 and synced to its Grok Bot computer, so another desktop installation needs

112 its own.

106* It does not review every side effect; memory writes and most settings changes113* It does not review every side effect; memory writes and most settings changes

107 are examples. Treat it as a complement to explicit boundaries and least114 are examples. Treat it as a complement to explicit boundaries and least

108 privilege, working alongside controls that do not depend on a model's115 privilege, working alongside controls that do not depend on a model's


142 one-time codes never belong in ordinary chat. See149 one-time codes never belong in ordinary chat. See

143 [Enter passwords and verification codes yourself](/grok-bot/approvals-security-and-privacy#enter-passwords-and-verification-codes-yourself).150 [Enter passwords and verification codes yourself](/grok-bot/approvals-security-and-privacy#enter-passwords-and-verification-codes-yourself).

144 151 

145To revoke access quickly, an organization admin terminates the member's152To end a member's current work, an organization admin terminates the member's

146computer from the dashboard; that computer management control is Enterprise153computer from the dashboard; see

147only. The durable disk is kept, and the next session starts a fresh computer.154[Manage Grok Bot computers](/grok-bot/computers). That control is Enterprise

148Revoke sessions in your identity provider as well. Application sessions persist155only. It stops running Bots, keeps the durable disk, and the member's next

156session starts a fresh computer. It does not remove access. To remove access,

157remove the member from the team or turn off Grok Bot for their group, and

158revoke their sessions in your identity provider. Application sessions persist

149only on the member's computer.159only on the member's computer.

150 160 

151When a project or login should no longer be available, members clean up161When a project or login should no longer be available, members clean up


157## Logging and audit167## Logging and audit

158 168 

159Audit Logs and Action Recording use separate pipelines. Audit Logs cover169Audit Logs and Action Recording use separate pipelines. Audit Logs cover

160administrative and security events. Action Recording captures Bot actions, and170administrative and security events, including Grok Bot control-plane actions.

161OpenTelemetry Export sends those events to your collector when configured.171Action Recording captures Bot actions, and OpenTelemetry Export sends those

172events to your collector when configured, tagged `cursor.surface=grok_bot`.

162 173 

163* Audit logs are Enterprise only. They cover admin, security, and174* Audit logs are Enterprise only. They cover admin, security, and

164 authentication events. View them in the dashboard or stream them to your175 authentication events, plus Grok Bot control-plane events: Bot creation,

165 SIEM. Self-serve Teams do not get this log.176 member access changes, Team Setup manifests, MCP authentication, Slack

177 account links, and routines. Filter them by application in the dashboard, or

178 stream them to your SIEM. Self-serve Teams do not get this log.

166* Action Recording is Enterprise only. It is a setting on the Grok Bot page,179* Action Recording is Enterprise only. It is a setting on the Grok Bot page,

167 off by default. When a team enables it, Cursor records Bot actions, including180 off by default. When a team enables it, Cursor records Bot actions, including

168 scrubbed shell commands, in an internal store with a 90-day retention. Action181 scrubbed shell commands, in an internal store with a 90-day retention. Action


203 216 

204## Data residency217## Data residency

205 218 

206Grok Bot computers run in the United States today. If your review needs a219Grok Bot computers run in the United States today. That is not the same as

220Cursor's

221[US-only data residency](https://cursor.com/docs/enterprise/privacy-and-data-governance#data-residency)

222program, which does not apply to Grok Bot by default. If your review needs a

207written residency commitment, contact your account team.223written residency commitment, contact your account team.

208 224 

209## Models and data225## Models and data


240command. Members choose the policy under256command. Members choose the policy under

241**Settings → General → Agent → Execution on Local Computer**: ask every time,257**Settings → General → Agent → Execution on Local Computer**: ask every time,

242always allow, or never. Recommend **Never** unless a Bot has a specific reason258always allow, or never. Recommend **Never** unless a Bot has a specific reason

243to work on local files. Local execution can be disabled entirely, and a259to work on local files. Admins can cap the policy for the whole team with

244team-level ceiling is enforced through settings; a dashboard control for the260[Execution on Local Computer](/grok-bot/teams-and-enterprises#execution-on-local-computer)

245ceiling is not available today. For the member-facing steps, see261on the Grok Bot page; a member's own setting still applies when it is

262stricter. For the member-facing steps, see

246[Control access to your local computer](/grok-bot/approvals-security-and-privacy#control-access-to-your-local-computer).263[Control access to your local computer](/grok-bot/approvals-security-and-privacy#control-access-to-your-local-computer).

247 264 

248## Hosting265## Hosting

249 266 

250Grok Bot runs only on Cursor-hosted cloud computers. On-premises deployment,267Grok Bot runs only on Cursor-hosted cloud computers. On-premises deployment,

251deployment inside your own perimeter, and bring-your-own-image deployment are268deployment inside your own perimeter, and bring-your-own-image deployment are

252not supported today, and Cursor does not operate a VPN, tunnel, or private link269not supported today. Hosted computers use shared static egress by default.

253into your network for Grok Bot. The supported model is shared static egress270Members can route traffic through their desktop, and Enterprise teams can

254combined with the destination allowlist. Team Setup is Enterprise only; those271install a networking client with **Team Setup**. See

255teams can install their own networking client on every team computer to reach

256private services. See

257[Connect to private networks](/grok-bot/private-networks).272[Connect to private networks](/grok-bot/private-networks).

258 273 

259## Prompt injection274## Prompt injection


283* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)298* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)

284* [Configure identity and access](/grok-bot/identity-and-access)299* [Configure identity and access](/grok-bot/identity-and-access)

285* [Connect to private networks](/grok-bot/private-networks)300* [Connect to private networks](/grok-bot/private-networks)

301* [Configure TLS-inspecting proxies](/grok-bot/proxies)

302* [Manage Grok Bot computers](/grok-bot/computers)

286* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)303* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)

287* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)304* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)

288 305 

security-faq.md +35 −16

Details

52Groups can set their own policy, and a lock makes the team policy effective for52Groups can set their own policy, and a lock makes the team policy effective for

53everyone. The organization-wide enable switch is also Enterprise only and53everyone. The organization-wide enable switch is also Enterprise only and

54applies to the whole organization. Cloud Agents, Team Rules, and public54applies to the whole organization. Cloud Agents, Team Rules, and public

55template sharing apply to the whole team on Teams and Enterprise.55template sharing apply to the whole team on Teams and Enterprise. Enforce

56Auto-review and Auto-review rules are Enterprise only and also apply to the

57whole team. Allow Local Egress is Enterprise only and applies to the whole

58team.

56 59 

57### Why do some websites block Bots?60### Why do some websites block Bots?

58 61 


68 71 

69### Can traffic run through our own network?72### Can traffic run through our own network?

70 73 

71Cursor does not operate a VPN, tunnel, or private link into your network for74Yes. A member can route a Grok Bot computer's web traffic through their

72Grok Bot. The supported paths are shared static egress with the destination75desktop, using its network and IP address. Enterprise teams can also install a

73allowlist, and installing your own networking client through Team Setup, which76networking client on every hosted computer through Team Setup. See

74is Enterprise only. See

75[Connect to private networks](/grok-bot/private-networks).77[Connect to private networks](/grok-bot/private-networks).

76 78 

79### Grok Bot hangs at computer setup from our network. Why?

80 

81A TLS-inspecting gateway such as Zscaler is letting `api2.cursor.sh` through

82and blocking or inspecting the computer's nested `cursorvm.com` hostname. Chat

83may or may not keep working; the computer link fails either way. Allow

84`*.cursorvm.com` and `*.*.cursorvm.com`, exempt them from inspection, and apply

85the change to off-network profiles too. See

86[Configure TLS-inspecting proxies](/grok-bot/proxies).

87 

77## Approvals, logging, and data88## Approvals, logging, and data

78 89 

79### What does Auto Review check?90### What does Auto Review check?


82computer use, automation writes, and delegation such as Cloud Agent and93computer use, automation writes, and delegation such as Cloud Agent and

83subagent launches. It can let an action proceed, require approval, or deny it.94subagent launches. It can let an action proceed, require approval, or deny it.

84It does not review every side effect, such as memory writes and most settings95It does not review every side effect, such as memory writes and most settings

85changes. Each member's own setting remains the off switch; an96changes. On Enterprise, team admins can enforce Auto-review from the Grok Bot

86organization-level lock is not available. See97page and add team Auto-review rules that every member inherits. Members can add

98stricter personal rules on top, and **Ask first** wins when rules conflict. If

99an admin turns enforcement off, members go back to their own rules only. See

87[approvals and Auto Review](/grok-bot/security#approvals-and-auto-review).100[approvals and Auto Review](/grok-bot/security#approvals-and-auto-review).

88 101 

89### Can I see what Bots did on behalf of my team?102### Can I see what Bots did on behalf of my team?

90 103 

91Spend and usage are on the dashboard usage page, broken down by product. Audit104Spend and usage are on the dashboard usage page, broken down by product. Audit

92logs are Enterprise only; they cover admin, security, and authentication events105logs are Enterprise only; they cover admin, security, and authentication

93and can stream to your SIEM. Action Recording is Enterprise only and is a106events, plus Grok Bot control-plane events like Bot creation, access changes,

94separate setting, off by default; when enabled, it records Bot actions107Team Setup, and routines, filterable by application, and can stream to your

95internally. OpenTelemetry Export is Enterprise only; configure it to receive108SIEM. Action Recording is Enterprise only and is a separate setting, off by

96those events in your own collector. They do not appear on the Audit Log page.109default; when enabled, it records Bot actions internally. OpenTelemetry Export

110is Enterprise only; configure it to receive those events in your own

111collector, tagged `cursor.surface=grok_bot`. They do not appear on the Audit

112Log page.

97See [logging and audit](/grok-bot/security#logging-and-audit).113See [logging and audit](/grok-bot/security#logging-and-audit).

98 114 

99### Can I restrict which models Grok Bot uses?115### Can I restrict which models Grok Bot uses?


106 122 

107### Where do Grok Bot computers run?123### Where do Grok Bot computers run?

108 124 

109In the United States today. If your review needs a written residency125In the United States today. That is not the same as Cursor's US-only data

110commitment, contact your account team.126residency program, which does not apply to Grok Bot by default. If your review

127needs a written residency commitment, contact your account team. See

128[data residency](/grok-bot/security#data-residency).

111 129 

112### Can we run Grok Bot on-premises or from our own image?130### Can we run Grok Bot on-premises or from our own image?

113 131 


124### Why do members have to sign in to company tools again?142### Why do members have to sign in to company tools again?

125 143 

126Sign-in sessions inside the computer can drop when the computer is recreated,144Sign-in sessions inside the computer can drop when the computer is recreated,

127for example after an image update or a policy change. Sessions ride your145for example after an image update or when an admin recreates it. Sessions ride

128identity provider, so your session policies also apply.146your identity provider, so your session policies also apply.

129 147 

130### What happens to data when an admin terminates a computer?148### What happens to data when an admin terminates a computer?

131 149 


147* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)165* [Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises)

148* [Configure identity and access](/grok-bot/identity-and-access)166* [Configure identity and access](/grok-bot/identity-and-access)

149* [Connect to private networks](/grok-bot/private-networks)167* [Connect to private networks](/grok-bot/private-networks)

168* [Configure TLS-inspecting proxies](/grok-bot/proxies)

150* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)169* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)

151* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)170* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)

Details

35 35 

36### Auto-review36### Auto-review

37 37 

38Manage your personal Auto Review rules.38Manage your personal Auto Review rules, plus any team rules your admin

39requires.

39 40 

40Two settings in **General** deserve care. **Execution on Local Computer**41Two settings in **General** deserve care. **Execution on Local Computer**

41controls whether Bots can run commands on the desktop in front of you;42controls whether Bots can run commands on the desktop in front of you;

42per-command approval is the default, and the setting applies to that desktop43per-command approval is the default, and the setting applies to that desktop

43alone. Auto Review rules shape which actions stop for your approval, and they44alone. Auto Review rules shape which actions stop for your approval. When your

44are stored on the current desktop and synced to its Grok Bot computer. Either45admin enforces Auto Review for the team, the same table also shows locked team

45way, do not assume another desktop installation carries the same configuration.46rules with `Required by your admin. You can't edit or delete this rule.` You

46Read [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)47can add your own rules on top, but they only make behavior stricter; **Ask

48first** wins when rules conflict. If your admin turns enforcement off, you only

49see and use your own rules. Your personal rules are stored on the current

50desktop and synced to its Grok Bot computer. Either way, do not assume another

51desktop installation carries the same configuration. Read

52[Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)

47before changing either.53before changing either.

48 54 

55## Computer

56 

57### Route traffic through your desktop

58 

59Turn on **Route egress through this desktop** to send your Grok Bot computer's

60web traffic through the current desktop. Destinations see your desktop's IP

61address, and the Bot can reach networks available from that device.

62 

63The setting applies to one desktop. If your Enterprise admin turns off **Allow

64Local Egress**, the toggle turns off and locks with

65`Your team's admin has turned off local egress.` Any active route stops within

66five minutes. Your choice is preserved and takes effect again if the admin

67re-allows local egress.

68 

69For private network options and their tradeoffs, see

70[Connect to private networks](/grok-bot/private-networks).

71 

49## Plugins72## Plugins

50 73 

51Use **Marketplace** to discover plugins and packaged skills. Use **Yours** to74Use **Marketplace** to discover plugins and packaged skills. Use **Yours** to


70 93 

71## Team Setup94## Team Setup

72 95 

73On the Teams plan and the Enterprise plan, **Team Setup** shows the managed96Team Setup is Enterprise only. When an Enterprise admin provides a managed

74setup your admin provides for team computers. You can review or reinstall the97setup, **Team Setup** shows it here so you can review or reinstall the current

75current setup. Admins configure it from the dashboard; see98setup. Admins configure manifests from the dashboard; see

76[Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises#set-up-your-team).99[Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises#team-setup).

77 100 

78Do not place secret values directly in managed setup instructions.101Do not place secret values directly in managed setup instructions.

79 102 

Details

6research, operations, documents, browsing, and automations. This page is for6research, operations, documents, browsing, and automations. This page is for

7team and organization admins rolling Grok Bot out. Security reviewers should7team and organization admins rolling Grok Bot out. Security reviewers should

8start with [Grok Bot security](/grok-bot/security) and the8start with [Grok Bot security](/grok-bot/security) and the

9[Grok Bot security FAQ](/grok-bot/security-faq), and members who want to9[Grok Bot security FAQ](/grok-bot/security-faq). Members who want the approval

10understand the approval model they work inside can start there too.10model should start there too.

11 11 

12## Availability12## Availability

13 13 

14| Plan | Access |14| Plan | Access |

15| --- | --- |15| --- | --- |

16| Individuals | Included with every paid Cursor plan (Pro, Pro+, and Ultra), through an individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+ link, or with a one-time free trial |16| Individuals | Included with every paid Cursor plan, or through an individual SuperGrok link |

17| Teams | Included; every member has access, and usage follows the seat's allowance |17| Teams | Included; every member has access, and usage follows the seat's allowance |

18| Enterprise | Contact your Cursor account team to enable Grok Bot for your organization |18| Enterprise | Enable Grok Bot for your team from your dashboard |

19 19 

20That table is product access, not the admin control list. Grok Bot is included20That table is product access, not the admin control list. Grok Bot is included

21on Teams, and several settings are Enterprise only and do not appear for21on Teams. Several settings are Enterprise only and do not appear for

22self-serve Teams. The [admin controls](#admin-controls) table names each one.22self-serve Teams. [Admin controls](#admin-controls) marks each one.

23 23 

24[Plans and billing](https://cursor.com/help/grok-bot/plans) is the canonical24[Plans and billing](https://cursor.com/help/grok-bot/plans) is the canonical

25plan and usage matrix.25plan and usage matrix.

26 26 

27## Enabling Grok Bot for your team

28 

29On the Teams plan, Grok Bot is enabled by default, and every member has access

30without any admin action. It stays off for teams on Privacy Mode (Legacy) or on

31a [legacy request-based plan](https://cursor.com/docs/models-and-pricing#legacy-request-based-pricing).

32There is no switch to turn it off.

33 

34On the Enterprise plan, an admin turns it on from

35[Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot). Once

36enabled, you can give access to all team members or limit it to specific

37groups with **Manage Group Access**. Turning Grok Bot off blocks every member

38without deleting their computers.

39 

40Admins on either plan can bring members in with **Invite Team** on the Grok Bot

41page. Existing Cursor users on your team get an email with a download link. New

42users get an invitation to your Cursor team, by email or invite link, that also

43points them to Grok Bot. Teams that manage membership through SCIM see only the

44existing-users option.

45 

46## Before you roll out

47 

48* Move off Privacy Mode (Legacy). That setting blocks Grok Bot entirely, and

49 you are prompted to change it before enabling. Check the privacy setting in

50 Team Settings.

51* Plan for shared egress addresses. If your company restricts services by

52 source IP, see [static egress IPs](/grok-bot/security#static-egress-ips).

53* Clear your gateway. If member devices sit behind Zscaler or another

54 TLS-inspecting proxy, allow Cursor's domains, including the nested

55 `*.*.cursorvm.com` pattern, and exempt them from inspection before members

56 connect. See

57 [Configure TLS-inspecting proxies](/grok-bot/proxies).

58* Decide how members sign in to company tools from the computer. See

59 [identity and sign-ins](/grok-bot/security#identity-and-sign-ins).

60* Review the policies Grok Bot inherits: Team Rules and the connector policy on

61 every plan, plus team Auto-review rules and the MCP allowlist on Enterprise.

62 

27## Architecture63## Architecture

28 64 

29### How Grok Bot is built65### How Grok Bot is built

30 66 

31Grok Bot is a computer-use agent that operates applications, browsers, and67Grok Bot is a computer-use agent that operates applications, browsers, and

32development environments. It runs in Cursor's cloud, and each user's work68development environments. It runs in Cursor's cloud, and each user's work

33executes on a dedicated cloud computer. The desktop app (macOS, Windows, and69executes on a dedicated cloud computer. The desktop and mobile apps are thin

34Linux) and the mobile app (iOS and Android) are thin clients for chat, review,70clients for chat, review, and approvals.

35and approvals.

36 71 

37The security model rests on four principles:72The security model rests on four principles:

38 73 

39* Per-user isolation: each user's work runs in a dedicated Firecracker microVM,74* Per-user isolation. Each user's work runs in a dedicated Firecracker microVM,

40 a micro virtual machine with hardware-level separation from other users.75 a micro virtual machine with hardware-level separation from other users.

41* No access by default: a Bot can use only the accounts and plugins the user or76* No access by default. A Bot can use only the accounts and plugins the user or

42 team grants it.77 team grants it.

43* Human approval gates: sensitive actions require user approval, evaluated by78* Human approval gates. Sensitive actions require user approval, evaluated by

44 an independent review model called Auto Review.79 an independent review model called Auto Review.

45* Administrative control: team admins can set Team Rules, Cloud Agent80* Administrative control. Team admins can set Team Rules, Cloud Agent

46 delegation, and template sharing. Network Controls, Team Setup, Action81 delegation, template sharing, and the local execution ceiling. Network

47 Recording, and the organization-wide enable switch are Enterprise only.82 Controls, Team Setup, Allow Local Egress, Action Recording, Enforce

83 Auto-review, Auto-review rules, and the organization-wide enable switch are

84 Enterprise only.

48 85 

49The pieces fit together like this:86The pieces fit together like this:

50 87 

511. Local machine: chat, review, and approvals happen on the member's device,881. Local machine. Chat, review, and approvals happen on the member's device.

52 and work runs in the hosted computer. Optional89 Work runs in the hosted computer. Optional

53 [local execution](/grok-bot/security#local-execution) requires per-command90 [local execution](/grok-bot/security#local-execution) requires per-command

54 approval by default and can be turned off.91 approval by default and can be turned off.

552. Environment: one persistent Firecracker microVM per user, shared by every922. Environment. One persistent Firecracker microVM per user. Every Bot that

56 Bot that user runs. Admins manage Grok Bot from the Grok Bot page of the93 user runs shares that computer. Admins manage Grok Bot from the Grok Bot

57 [Cursor dashboard](https://cursor.com/dashboard/bot). Team Rules, Cloud94 page of the [Cursor dashboard](https://cursor.com/dashboard/bot). Team

58 Agent delegation, and public template sharing are available to team admins;95 Rules, Cloud Agent delegation, public template sharing, and Execution on

59 the organization-wide enable switch, Network Controls, Team Setup, Action96 Local Computer are available to team admins. Enterprise only on that page:

60 Recording, and computer management for organization admins are Enterprise97 the organization-wide enable switch, Network Controls, Team Setup, Allow

61 only. Members never see this page.98 Local Egress, Action Recording, Enforce Auto-review, Auto-review rules, and

623. The Bot: shell, browser, and computer use inside the hosted computer. A Bot99 computer management for organization admins. Members never see this page.

1003. The Bot. Shell, browser, and computer use inside the hosted computer. A Bot

63 has no access by default and acts only with accounts the member signs it101 has no access by default and acts only with accounts the member signs it

64 into; it hands login, two-factor authentication, and payment steps to the102 into. It hands login, two-factor authentication, and payment steps to the

65 member.103 member.

664. Plugins: your team's Cursor MCP (Model Context Protocol) policy applies in1044. Plugins. Your team's Cursor MCP (Model Context Protocol) policy applies in

67 full, allowing or blocking each connector. OAuth tokens stay on Cursor's105 full, allowing or blocking each connector. OAuth tokens stay on Cursor's

68 connector backend, and Bots invoke tools without receiving them.106 connector backend, and Bots invoke tools without receiving them.

695. Cloud Agents: Grok Bot can delegate coding tasks to separate computers under1075. Cloud Agents. Grok Bot can delegate coding tasks to separate computers under

70 your existing [Cloud Agent](https://cursor.com/docs/cloud-agent) controls.108 your existing [Cloud Agent](https://cursor.com/docs/cloud-agent) controls.

71 Admins can disable spawning.109 Admins can disable spawning.

726. Models and data: Cursor manages model selection. With Privacy Mode enabled,1106. Models and data. Cursor manages model selection. With Privacy Mode enabled,

73 customer data is not used for training; Cursor enforces this on its servers,111 customer data is not used for training; Cursor enforces this on its servers,

74 and when the setting cannot be verified, the system defaults to not training.112 and when the setting cannot be verified, the system defaults to not training.

75 113 


86temporary files when work completes. When a workload needs its own computer and124temporary files when work completes. When a workload needs its own computer and

87credential set, give it its own Cursor user.125credential set, give it its own Cursor user.

88 126 

89## Roll out Grok Bot127## Admin controls

90 128 

91### Before you roll out129Most Grok Bot settings sit on the Grok Bot page of the

130[Cursor dashboard](https://cursor.com/dashboard/bot), which only admins see. A

131few live in Team Settings, your Team Marketplace, or your identity provider.

132Several controls are available only on the Enterprise plan; the rest are

133available on Teams and Enterprise.

92 134 

93* Move off Privacy Mode (Legacy). That setting blocks Grok Bot entirely, and135### Access and identity

94 you are prompted to change it before enabling. Check the privacy setting in

95 Team Settings.

96* Plan for shared egress addresses. If your company restricts services by

97 source IP, see [static egress IPs](/grok-bot/security#static-egress-ips).

98* Decide how members sign in to company tools from the computer. See

99 [identity and sign-ins](/grok-bot/security#identity-and-sign-ins) and, for

100 Okta and Microsoft Entra ID steps,

101 [Configure identity and access](/grok-bot/identity-and-access).

102* Review the policies Grok Bot inherits: Team Rules and Auto Review team

103 instructions, which are on Teams and Enterprise. The MCP allowlist is

104 Enterprise only.

105 136 

106### Set up your team137Who can use Grok Bot, and how members are provisioned.

107 138 

1081. Open [Grok Bot in the Cursor dashboard](https://cursor.com/dashboard/bot).139#### Enable Grok Bot

109 **Enable Grok Bot** is Enterprise only; **Enable** opens a setup modal that

110 covers privacy mode, pricing, and model availability. Self-serve Teams see

111 **Learn more** and an onboarding path, not an organization-wide switch.

1122. Configure Network Controls (Enterprise only). Teams without a policy default

113 to allow-all, and self-serve Teams do not see this panel. See

114 [network policy](/grok-bot/security#network-policy) for the modes.

1153. Audit your connector policy. Any permitted connector is available to every

116 Bot a member runs; see the **Connector policy** entry under

117 [admin controls](#admin-controls).

1184. Review the delegation and sharing defaults. Check the **Cloud Agents** and

119 **Public template sharing** entries under [admin controls](#admin-controls);

120 both ship with permissive defaults.

121 140 

122### Admin controls141The organization-wide switch on the Grok Bot page, with **Manage Group Access**

142beside it. Turning it on opens a setup modal that covers privacy mode, pricing,

143and model availability. Turning it off blocks every member without deleting

144their computers. See

145[Enabling Grok Bot for your team](#enabling-grok-bot-for-your-team).

123 146 

124Most Grok Bot settings sit on the Grok Bot page of the147Available on the Enterprise plan.

125[Cursor dashboard](https://cursor.com/dashboard/bot), and that page is148 

126admin-only. Enterprise only means the control is hidden on self-serve Teams; it149#### SCIM

127is not a default you can turn on later.150 

128 151SCIM 2.0 provisioning and deprovisioning through your identity provider.

129| Control | Availability | Where |152Members sign in to Grok Bot with their Cursor account, so your existing

130| --- | --- | --- |153[SCIM](https://cursor.com/docs/account/teams/scim) and SSO setup carries over.

131| Enable Grok Bot | Enterprise only | Grok Bot page |154For Okta and Entra ID steps, including app assignment and sign-in rules for the

132| Network Controls | Enterprise only | Grok Bot page |155computer browser, see

133| Team Setup | Enterprise only | Grok Bot page |156[Configure identity and access](/grok-bot/identity-and-access).

134| Action Recording | Enterprise only | Grok Bot page |157 

135| Computer management | Enterprise only; organization admins | Grok Bot page |158Available on the Enterprise plan.

136| Cloud Agents | Teams and Enterprise | Grok Bot page |159 

137| Public template sharing | Teams and Enterprise | Grok Bot page |160### Agent capabilities

138| Team Rules | Teams and Enterprise | Grok Bot page |161 

139| Connector policy | Teams and Enterprise; the MCP allowlist is Enterprise only | Teams Marketplace |162What Bots may do on behalf of members. Each control applies to every member's

140| Auto Review team instructions | Teams and Enterprise | Team Settings, Security and Automation |163Bots.

141| Audit logs | Enterprise only | Dashboard audit log, or SIEM stream |164 

142| OpenTelemetry Export | Enterprise only | Team Settings |165#### Cloud Agents

143| SCIM | Enterprise only | Identity provider |166 

144 167Allows or blocks Bots delegating coding tasks to Cursor Cloud Agents. The

145* **Enable Grok Bot.** Enterprise only. An organization-wide switch. Incomplete168switch is on the Grok Bot page, applies to the whole team, and is on by

146 setup shows **Disabled** and **Enable**; after setup, the page shows169default. Delegated work runs on separate computers under your existing

147 **Enabled** and **Disable**. Disabling blocks members and does not delete170[Cloud Agent](https://cursor.com/docs/cloud-agent) controls. Turn it off when

148 member computers. Self-serve Teams do not get this switch; their dashboard171your team does not need delegation.

149 shows **Learn more**, and a first admin visit can open onboarding at172 

150 `/bot/onboarding` in the dashboard.173#### Public template sharing

151* **Network Controls.** Enterprise only. Four modes, directory-group scope, and174 

152 a lock. The dashboard label is **Network Controls**. Self-serve Teams have no175Controls whether members can publish Bot templates outside your team. Off

153 destination allowlist. See176keeps sharing team-only, and Cursor enforces the policy on its servers,

154 [network policy](/grok-bot/security#network-policy).177including for templates that are already public. Enterprise teams start with

155* **Team Setup.** Enterprise only. Manifests of admin install scripts that run178public sharing off; other teams start with it allowed. For what a shared

156 on every team computer, so your standard tooling is in place everywhere. Do179template contains, see [Share a Bot](/grok-bot/bots#share-a-bot).

157 not put secret values in setup scripts. To install your own networking client180 

158 and reach private services, see181#### Connector policy

159 [Connect to private networks](/grok-bot/private-networks).182 

160* **Action Recording.** Enterprise only. Records Bot actions and is off by183Grok Bot inherits your team's Cursor connector policy. There is no separate

161 default. Events do not appear on the Audit Log page. To receive them in your184Grok Bot connector list, and connectors appear as plugins in the app. Set which

162 own collector, configure185servers members can use from your Team Marketplace on the dashboard's

163 [OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export),186[Plugins page](https://cursor.com/dashboard/plugins), not on the Grok Bot page.

164 which is also Enterprise only. See187The MCP allowlist is Enterprise only; see

165 [logging and audit](/grok-bot/security#logging-and-audit).188[MCP server trust management](https://cursor.com/docs/enterprise/model-and-integration-management#mcp-server-trust-management).

166* **Computer management.** Enterprise only. Organization admins can look up any189Any permitted connector is available to every Bot a member runs, and a blocked

167 member's computer, see when it was created and last active, and terminate190one shows as **Disabled by team admin**. Pushing connectors to members, whether

168 it. Team admin rights are not enough, because a computer spans every team191mandatory or default-on, is not available.

169 the member belongs to. The durable disk is kept, and the member's next192 

170 session starts a fresh computer.193#### Execution on Local Computer

171* **Cloud Agents.** Teams and Enterprise. Allow or block delegation to Cursor194 

172 Cloud Agents. The default is on, and the toggle applies to the whole team.195Caps what Bots may do on a member's own machine through the desktop app: open

173* **Public template sharing.** Teams and Enterprise. Off keeps Bot template196files and run tasks. Pick **Always allow**, **Ask every time**, or **Never

174 sharing within your team, and the policy is enforced on Cursor's servers,197allow** on the Grok Bot page. **Always allow**, the default, leaves the choice

175 including for existing public templates. Enterprise teams start with public198to each member, whose own setting defaults to asking before every task. **Ask

176 sharing off; other teams start with it allowed. The control itself is on199every time** makes every local task ask for approval, and **Never allow** turns

177 both plans.200local execution off for the whole team. A member's own setting still applies

178* **Team Rules.** Teams and Enterprise. Rules applied for every member's Bots.201when it is stricter than the team's. Pick **Never allow** unless Bots have a

179 Rules are always required and cannot be made optional, and you scope each202specific reason to work on member machines. See

180 rule to Cursor, Grok Bot, or both. Keep them short and few, like "never move203[local execution](/grok-bot/security#local-execution).

181 company data to personal accounts"; for enforcement, use Auto Review204 

182 instructions instead.205#### Allow Local Egress

183* **Auto Review team instructions.** Teams and Enterprise. Team-wide allow and206 

184 block instructions that feed the reviewer's decisions for every member.207Let members route Grok Bot's web traffic through their own computer. Off

185 These live in team settings under Security and Automation, not on the Grok208disables the option in Grok Bot. The switch is on by default. Turning it off

186 Bot page.209stops active routes within five minutes. Turning it back on restores each

187* **Local execution.** The policy for Bots acting on a member's own machine.210member's previous choice. See

188 See [local execution](/grok-bot/security#local-execution). A dashboard211[Route traffic through your desktop](/grok-bot/settings-and-notifications#route-traffic-through-your-desktop).

189 control for the team ceiling is not available on any plan.212 

190* **Connector policy.** Grok Bot inherits your team's Cursor connector policy.213Available on the Enterprise plan.

191 There is no separate Grok Bot connector list, and connectors appear as214 

192 plugins in the app. Configure marketplace require and restrict in Teams215### Rules and approvals

193 Marketplace (Integrations), not on the Grok Bot page. The MCP allowlist is216 

194 Enterprise only; see217Guidance Bots follow, and the review layer that stops actions.

195 [MCP server trust management](https://cursor.com/docs/enterprise/model-and-integration-management#mcp-server-trust-management).218 

196 When policy blocks a server, members see the plugin as219#### Team Rules

197 **Disabled by team admin**. Provisioning connectors to members, whether220 

198 mandatory or default-on, is not available.221Rules that every member's Bots follow. Add them from the Grok Bot page and

199* **Audit logs.** Enterprise only. Admin, security, and authentication events.222scope each rule to Cursor, Grok Bot, or both. Rules applied to Grok Bot are

200 View them in the dashboard or stream them to your SIEM. Self-serve Teams do223always required, so members cannot turn them off. Keep them short and few, like

201 not get this log.224"never move company data to personal accounts." Rules guide a Bot; for approval

202* **OpenTelemetry Export.** Enterprise only. The customer path for Action225behavior, use [Auto-review rules](#auto-review-rules).

203 Recording events. Configure it under Team Settings; see226 

204 [OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export).227#### Enforce Auto-review

205* **SCIM.** Enterprise only. SCIM 2.0 provisioning and deprovisioning. See228 

206 [Configure identity and access](/grok-bot/identity-and-access).229Prevents members from turning Auto-review off. The switch is on the Grok Bot

230page and is off by default. When it is on, Bots always check risky actions

231before running them and ask for approval when needed. Turn it on before you

232rely on team Auto-review rules.

233 

234Available on the Enterprise plan.

235 

236#### Auto-review rules

237 

238Team-wide **Ask first** and **Allow automatically** rules that apply to every

239member's Bots on top of their own rules. Add them with **Configure Rules** on

240the Grok Bot page; changes save automatically. Members see the team rules under

241**Settings → General → Auto-review** but cannot edit or delete them, and **Ask

242first** wins when rules conflict. Turning enforcement off stops applying the

243team rules. See

244[approvals and Auto Review](/grok-bot/security#approvals-and-auto-review).

245 

246Available on the Enterprise plan.

247 

248### Computers and network

249 

250How team computers are set up, what they can reach, and how you recreate or

251terminate them.

252 

253#### Network Controls

254 

255Restricts which destinations team computers can reach. Pick one of four modes,

256from allow-all to a team allowlist of domains and IP ranges. Directory groups

257can carry their own policy, and a lock makes the team policy apply to everyone.

258Teams without a policy default to allow-all. See

259[network policy](/grok-bot/security#network-policy) for the modes and how a

260new policy reaches running computers.

261 

262Available on the Enterprise plan.

263 

264#### Team Setup

265 

266Manifests of install scripts that run on every team computer, so the same

267tooling is present everywhere. Keep secret values out of setup scripts. Members

268see the managed setup under

269[Team Setup](/grok-bot/settings-and-notifications#team-setup) in the app,

270where they can review or reinstall it. For how manifests run, and to install a

271networking client that reaches private services, see

272[Connect to private networks](/grok-bot/private-networks).

273 

274Available on the Enterprise plan.

275 

276#### Grok Bot Computers

277 

278Lets organization admins recreate or terminate the computers of many members

279at once, with a result for each member. Team admin rights are not enough,

280because one computer spans every team the member belongs to. **Recreate** moves

281members to the latest image and Team Setup while keeping their Bots, files, and

282logins. **Terminate** ends the member's current work and keeps the durable

283disk; the member's next session starts a fresh computer on it. Neither action

284removes access: to do that, remove the member from the team or turn off Grok

285Bot for their group, and revoke their sessions in your identity provider. See

286[Manage Grok Bot computers](/grok-bot/computers).

287 

288Available on the Enterprise plan.

289 

290### Logging and audit

291 

292What gets recorded, and where it goes.

293 

294#### Action Recording

295 

296Records Bot actions: connector (MCP) tool calls, shell commands, browser

297navigations, and computer use sessions. Events are sanitized before they are

298stored or exported. Shell commands are secret-scrubbed; browser navigations

299keep each page as `scheme://host/path` with the title but strip query strings

300and credentials; computer use sessions record action and screenshot counts and

301the session duration, without the screenshots, clicks, or typed text. The

302switch is on the Grok Bot page and is off by default. Recorded events do not

303appear on the Audit Log page. To receive them in your own collector, configure

304[OpenTelemetry Export](#opentelemetry-export), which delivers each event

305tagged `cursor.surface=grok_bot`. Retention details are on

306[logging and audit](/grok-bot/security#logging-and-audit).

307 

308Available on the Enterprise plan.

309 

310#### Audit logs

311 

312Admin, security, and authentication events, plus Grok Bot control-plane

313events: Bot creation, member access changes, Team Setup manifests, MCP

314authentication, Slack account links, and routines. Each row names the

315application that acted, so you can filter the log to Grok Bot. View them on the

316[Audit Log page](https://cursor.com/dashboard/audit-log) or stream them to

317your SIEM; see

318[audit logs](https://cursor.com/docs/enterprise/compliance-and-monitoring#audit-logs).

319For the actions Bots took, use [Action Recording](#action-recording).

320 

321Available on the Enterprise plan.

322 

323#### OpenTelemetry Export

324 

325Streams Cursor usage metrics and logs, including recorded Grok Bot actions, to

326a collector you run. It is the customer path for Action Recording events.

327Configure it under **Team Settings → OpenTelemetry Export**. Endpoint

328requirements and the event schema are on

329[OpenTelemetry Export](https://cursor.com/docs/enterprise/opentelemetry-export).

330 

331Available on the Enterprise plan.

332 

333## Admin API

334 

335Enable Grok Bot and manage capabilities, Enforce Auto-review, group access,

336network policy, team rules, and setup scripts through the

337[Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot).

207 338 

208## Security339## Security

209 340 

210The security model, network policy, approvals and Auto Review, identity,341The security model, network policy, approvals and Auto Review, identity,

211logging, data handling, hosting, and certifications live on342logging, data handling, and certifications live on

212[Grok Bot security](/grok-bot/security). Common review questions are on the343[Grok Bot security](/grok-bot/security). Common review questions are on the

213[Grok Bot security FAQ](/grok-bot/security-faq).344[Grok Bot security FAQ](/grok-bot/security-faq).

214 345 


218 349 

219For administrators:350For administrators:

220 351 

2211. Configure Network Controls (Enterprise only). Teams without a policy default3521. Configure Network Controls. Enterprise only. Teams without a policy default

222 to allow-all, and self-serve Teams cannot set this. See353 to allow-all. Self-serve Teams cannot set this. See

223 [network policy](/grok-bot/security#network-policy).354 [network policy](/grok-bot/security#network-policy).

2242. Audit connector policy in Teams Marketplace before enabling Grok Bot. Any3552. Audit connector policy in Teams Marketplace before enabling Grok Bot. Any

225 permitted connector is available to every Bot a member runs.356 permitted connector is available to every Bot a member runs.

2263. Ask members to keep Auto Review enforcement on. Enforcement is enabled by3573. Turn on Enforce Auto-review before you rely on team rules. Enterprise only.

227 Cursor and currently active for all users, and each member's own setting358 Members can add stricter personal rules on top, and **Ask first** wins when

228 remains the off switch.359 rules conflict.

2294. Set an explicit local execution policy, and decide whether Bots may act on3604. Set Execution on Local Computer to **Never allow** unless Bots need to act

230 member machines at all.361 on member machines. The default leaves the choice to each member.

2315. Disable Cloud Agent spawning if you do not need delegation.3625. Disable Cloud Agent spawning if you do not need delegation.

2326. Keep public template sharing off unless members should publish Bot3636. Keep public template sharing off unless members should publish Bot

233 templates outside the team.364 templates outside the team.

2347. Add team block instructions for actions that are never acceptable in your3657. Add team Auto-review rules. Enterprise only. Cover actions that should

235 environment, and allow instructions for routine safe work. Production366 always ask first or can proceed automatically. Production deployments,

236 deployments, external email, payments, and accepting legal terms are common367 external email, payments, and accepting legal terms are good **Ask first**

237 block examples.368 examples. Keep automatic rules narrow.

2388. Gate sign-in to managed devices through your identity provider. Grok Bot3698. Gate sign-in to managed devices through your identity provider. Grok Bot

239 sign-in uses your SSO, so a device-aware sign-in policy applies to it. This370 sign-in uses your SSO, so a device-aware sign-in policy applies to it. This

240 gates sign-in, not the hosted computer itself.371 gates sign-in, not the hosted computer itself.


258### Can I turn Grok Bot on or off for my team?389### Can I turn Grok Bot on or off for my team?

259 390 

260The organization-wide **Enable Grok Bot** switch is Enterprise only. It lives391The organization-wide **Enable Grok Bot** switch is Enterprise only. It lives

261on the Grok Bot page of the Cursor dashboard, and self-serve Teams do not get392on the Grok Bot page of the Cursor dashboard. Self-serve Teams do not get this

262it. Disabling blocks members without deleting their computers.393switch. Disabling blocks members without deleting their computers.

394 

395### Can I manage Grok Bot through the Admin API?

396 

397Yes. Use the

398[Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot).

263 399 

264### Can I set a Grok Bot spend cap?400### Can I set a Grok Bot spend cap?

265 401 


280### How do members request access?416### How do members request access?

281 417 

282Members can send a request from the app. On a pooled Enterprise team whose418Members can send a request from the app. On a pooled Enterprise team whose

283admin has not finished setup, members see a team-setup message instead; the419admin has not finished setup, members see a team-setup message instead. The

284next step is for an admin to use the Enterprise-only enable switch. Self-serve420next step is for an admin to use the Enterprise only enable switch. Self-serve

285Teams do not use that switch.421Teams do not use that switch.

286 422 

423### Can I see what kind of work my team does with Grok Bot?

424 

425Yes, on Enterprise teams where it has rolled out. The Conversation Insights

426page of the Analytics dashboard has a Grok Bot source that groups Bot

427conversations by Type of Work and Level of Automation. See

428[Grok Bot Conversation Insights](https://cursor.com/docs/account/teams/analytics#grok-bot-conversation-insights).

429 

287Isolation, egress, approvals, logging, and data-handling questions are on the430Isolation, egress, approvals, logging, and data-handling questions are on the

288[Grok Bot security FAQ](/grok-bot/security-faq).431[Grok Bot security FAQ](/grok-bot/security-faq).

289 432 


293* [Grok Bot security FAQ](/grok-bot/security-faq)436* [Grok Bot security FAQ](/grok-bot/security-faq)

294* [Configure identity and access](/grok-bot/identity-and-access)437* [Configure identity and access](/grok-bot/identity-and-access)

295* [Connect to private networks](/grok-bot/private-networks)438* [Connect to private networks](/grok-bot/private-networks)

439* [Configure TLS-inspecting proxies](/grok-bot/proxies)

440* [Manage Grok Bot computers](/grok-bot/computers)

296* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)441* [Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)

442* [Admin API](https://cursor.com/docs/account/teams/admin-api#grok-bot)

443* [Grok Bot Conversation Insights](https://cursor.com/docs/account/teams/analytics#grok-bot-conversation-insights)

297* [Plans and billing](https://cursor.com/help/grok-bot/plans)444* [Plans and billing](https://cursor.com/help/grok-bot/plans)

298* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)445* [Privacy and Data Governance](https://cursor.com/docs/enterprise/privacy-and-data-governance)

299 446 

Details

1313. Ask it to regenerate the action with the corrected scope1313. Ask it to regenerate the action with the corrected scope

132 132 

133If an action keeps requiring approval, check **Settings → General →133If an action keeps requiring approval, check **Settings → General →

134Auto-review** for a matching **Require Approval** rule. Require rules take134Auto-review** for a matching **Ask first** rule, including team rules your

135precedence over allow rules.135admin requires. **Ask first** rules take precedence over **Allow

136automatically** rules.

136 137 

137## Local computer work is refused138## Local computer work is refused

138 139