SpyBara
Go Premium

Documentation 2026-09-17 10:04 UTC to 2026-09-18 23:59 UTC

13 files changed +198 −151. View all changes and history on the product overview
2026
Tue 22 23:58 Mon 21 23:00 Sat 19 23:59 Fri 18 23:59 Wed 16 19:01 Fri 11 21:00 Mon 7 22:57
Details

34 34 

35* On desktop, **Allow once** lets the Bot continue with that action and35* On desktop, **Allow once** lets the Bot continue with that action and

36 **Deny** blocks it. **Always allow** can save a matching rule.36 **Deny** blocks it. **Always allow** can save a matching rule.

37* On iPhone and Android, the equivalent controls are **Approve once** and37* On iPhone and Android, the Auto-review sheet offers **Allow**, **Deny**, and,

38 **Deny**.38 when a rule is proposed, **Always allow**; a local-command card offers

39 **Allow once** and **Deny**.

39 40 

40Do not approve an action whose target or effect you cannot identify. Ask the Bot41Do not approve an action whose target or effect you cannot identify. Ask the Bot

41to explain it in plain language or produce a draft first.42to explain it in plain language or produce a draft first.


43## Configure Auto Review44## Configure Auto Review

44 45 

45With Auto Review on, Grok Bot evaluates tool calls and computer actions before46With Auto Review on, Grok Bot evaluates tool calls and computer actions before

46they run. Open **Settings → General → Auto-review** to add rules.47they run. Open **Settings → General → Bot → Auto-review** to add rules.

47 48 

48* **Ask first** rules always stop matching actions for you.49* **Ask first** rules always stop matching actions for you.

49* **Allow automatically** rules let matching actions proceed only when the50* **Allow automatically** rules let matching actions proceed only when the


65behavior change over time. Auto Review is model-based and should complement,66behavior change over time. Auto Review is model-based and should complement,

66not replace, least privilege and explicit approval boundaries.67not replace, least privilege and explicit approval boundaries.

67 68 

68Personal Auto-review rules are stored on the current desktop and synced to its69Personal Auto-review rules are saved to your account and applied on every

69Grok Bot computer. Verify them separately on another desktop installation.70desktop you sign in to, as well as on your Grok Bot computer.

70 71 

71## Enter passwords and verification codes yourself72## Enter passwords and verification codes yourself

72 73 


84the value in that request. It is not a general-purpose password manager. The85the value in that request. It is not a general-purpose password manager. The

85value is masked, excluded from the transcript, and not shown to the model.86value is masked, excluded from the transcript, and not shown to the model.

86 87 

88When a web page needs you to type something yourself, such as a login, a

89checkout address, or a phone number, the Bot can show a form in the chat, one

90form per step, and fill your answers into the page for you.

91 

92If you sign in with a hardware security key, such as a YubiKey, the Bot's

93browser can use a key plugged into your desktop while **Use hardware security

94keys** is on under **Settings → General → Security Key**. The setting is on by

95default on macOS and Windows and is not yet supported on Linux; every use asks

96you to approve it first.

97 

87## Control access to your local computer98## Control access to your local computer

88 99 

89The shared Grok Bot computer runs in the cloud. Access to the Mac or Windows100The shared Grok Bot computer runs in the cloud. Access to the Mac or Windows

90computer in front of you is a separate capability.101computer in front of you is a separate capability.

91 102 

92In **Settings → General → Agent → Execution on Local Computer**, choose whether103In **Settings → General → Bot → Execution on Local Computer**, choose

93local commands:104**Ask every time**, **Always allow**, or **Never allow**. Once your account has

105registered computers, the choice moves to **Settings → Computer → Computers**,

106where each computer has its own **Execution on this computer** setting.

94 107 

95* Always require approval108The default is **Ask every time**. Use **Never allow** unless a Bot has a

96* Are always allowed

97* Are never allowed

98 

99The default is **Ask every time**. Use **Never allowed** unless a Bot has a

100specific reason to work on your local files. Your team admin can cap this109specific reason to work on your local files. Your team admin can cap this

101setting for the whole team; when the team's policy is stricter than yours, the110setting for the whole team; when the team's policy is stricter than yours, the

102team's applies. These settings do not prevent the Bot from using its cloud111team's applies. These settings do not prevent the Bot from using its cloud

103computer.112computer.

104 113 

114The first time a Bot asks to run a command on your computer, the conversation

115shows **Allow Grok Bot and all Bots to run commands on your local computer?**

116with **Always allow**, **Allow once**, **Never**, and **Deny once** (Esc).

117**Always allow** and **Never** set **Execution on Local Computer** for every

118Bot, and you can change the setting later in Settings. If your team's admin has

119set a stricter ceiling, **Always allow** is unavailable.

120 

105## Understand the shared-computer boundary121## Understand the shared-computer boundary

106 122 

107All of your Bots share one cloud computer assigned to your user account. Files,123All of your Bots share one cloud computer assigned to your user account. Files,

bots.md +24 −16

Details

29## Create a Bot29## Create a Bot

30 30 

311. Choose **New** in the sidebar or press `Cmd/Ctrl+N`.311. Choose **New** in the sidebar or press `Cmd/Ctrl+N`.

322. In **New chat**, select **Create new agent**.322. In **New chat**, select **Create new Bot**, or type a name and choose

333. Grok Bot creates and opens a Bot named **New Agent**.33 **Create “name” Bot**.

344. Open **Bot actions → Edit Profile** to set its name, title, description,343. Grok Bot creates and opens a Bot named **New Bot**.

354. Open **Bot actions → Edit Profile** to set its name, label, description,

35 and avatar.36 and avatar.

365. Start a conversation with a concrete task.375. Start a conversation with a concrete task.

37 38 


56* **Pin** active Bots to keep them at the top of the sidebar.57* **Pin** active Bots to keep them at the top of the sidebar.

57* **Hide from sidebar** removes a Bot from the main list without deleting its58* **Hide from sidebar** removes a Bot from the main list without deleting its

58 work.59 work.

59* Open **Show hidden chats** at the bottom of the sidebar, then choose60* Open **Hidden Bots** at the bottom of the sidebar (when every Bot is hidden,

60 **Unhide**, to restore a hidden Bot.61 the sidebar shows **Show Hidden Bots** instead), then choose **Unhide** to

62 restore a hidden Bot.

61 63 

62Hiding does not pause the Bot or its routines.64Hiding does not pause the Bot or its routines.

63 65 


73 75 

74## Share a Bot76## Share a Bot

75 77 

76Share a public link when someone else should start from the same Bot.78Share a template when someone else should start from the same Bot.

77 79 

781. Open the Bot and copy its share link.801. Open **Bot actions** (or the conversation details) and choose **Share as

792. Send the link. The recipient opens a preview on81 template**. The Bot builds the template; when it is ready, **Copy link**,

80 [x.ai](https://x.ai) and can choose **Add to Grok Bot**.82 **View template details**, and **Update template** appear.

813. They need the Grok Bot app to finish adding it.832. Choose who can open the link: **Public link** or **Team-only**. Accounts on

82 84 an Enterprise plan default to **Team-only**; other accounts default to a

83The link is public. Anyone who has it can view the Bot's shared configuration,85 public link.

84including its identity, description, skills, and routines. Remove API keys,863. Send the link. The recipient opens a preview on

85internal URLs, customer data, and anything else you would not put in a public87 [x.ai](https://x.ai) and can choose **Add to Grok Bot**. They need the Grok

86document before you share.88 Bot app to finish adding it.

89 

90A public link can be opened by anyone who has it and shows the Bot's shared

91configuration, including its identity, description, skills, and routines; a

92Team-only link opens only for members of your team. Remove API keys, internal

93URLs, customer data, and anything else you would not put in a public document

94before you share.

87 95 

88Adding a shared Bot creates a copy on the recipient's account. It does not give96Adding a shared Bot creates a copy on the recipient's account. It does not give

89them your computer, logins, or conversation history.97them your computer, logins, or conversation history.

Details

61## Connect an app61## Connect an app

62 62 

63Connectors give a Bot a structured way to work with supported services.63Connectors give a Bot a structured way to work with supported services.

64Connectors are shown as **Plugins** in the current app.64Connectors are installed as plugins from **Marketplace**.

65 65 

661. Open **Settings → Plugins**.661. Open **Marketplace** from the sidebar.

672. Browse the available connectors.672. Browse the available plugins.

683. Choose **Add**.683. Choose **Add**.

694. Complete authentication in your browser if requested.694. Complete authentication in your browser if requested.

705. In chat, type `@` to attach the connector to the task. Type `/` to reference705. In chat, type `@` to attach the connector to the task. Type `/` to reference


89 89 

90## Update, recover, or reset the computer90## Update, recover, or reset the computer

91 91 

92When the computer is unreachable, use **Recover computer** from the error state.92When the computer is unreachable, use **Recover computer** from the error state

93For planned maintenance or last-resort recovery, open **Settings → Beta**:93(the confirmation dialog calls it **Recover Grok Bot's Computer**). Recovery is

94offered only there, not in Settings. For planned maintenance or last-resort

95recovery, open **Settings → Updates** and use the **Grok Bot's Computer**

96controls:

94 97 

95* **Update Agent Computer** rebuilds with the latest image while preserving98* **Update** installs the latest software on the computer and keeps your files

96 durable state.99 in place.

97* **Recover Agent Computer** replaces an unreachable computer while preserving100* **Reset** rebuilds the computer from your last saved snapshot; very recent

98 durable state when that action is offered.101 changes may be lost.

99* **Reset Agent Computer** returns to the most recent durable snapshot and can

100 discard recent unsaved work.

101 102 

102Wait for active work to finish before recovery when possible. See103Wait for active work to finish before recovery when possible. See

103[Troubleshooting](/grok-bot/troubleshooting) for the least-destructive order.104[Troubleshooting](/grok-bot/troubleshooting) for the least-destructive order.

faq.md +12 −9

Details

60approval. Passwords, two-factor codes, CAPTCHAs, and similar human-only steps60approval. Passwords, two-factor codes, CAPTCHAs, and similar human-only steps

61use a computer takeover.61use a computer takeover.

62 62 

63Put standing boundaries in each Bot's description and add narrow **Require63Put standing boundaries in each Bot's description and add narrow **Ask first**

64Approval** rules for actions such as sending, publishing, deleting, purchasing,64rules for actions such as sending, publishing, deleting, purchasing, or

65or changing production systems.65changing production systems.

66 66 

67## How does Grok Bot handle data and privacy?67## How does Grok Bot handle data and privacy?

68 68 


76 76 

77## How much does Grok Bot cost?77## How much does Grok Bot cost?

78 78 

79Availability and billing depend on the account and plan. Eligible plans include79Availability and billing depend on the account and plan. Grok Bot is included

80SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra, and Cursor Teams80with every paid individual Cursor plan and with the Cursor Teams plan, and you

81Standard and Premium. Grok Bot subscriptions include weekly usage; eligible81can link an individual SuperGrok, SuperGrok Plus, or SuperGrok Heavy

82subscription. Grok Bot subscriptions include weekly usage; eligible

82accounts can add on-demand usage billed from model and token cost. If you have83accounts can add on-demand usage billed from model and token cost. If you have

83both a Cursor and a SuperGrok subscription, Grok Bot uses whichever has more84both a Cursor and a SuperGrok subscription, Grok Bot uses whichever has more

84usage. Review the current access page or85usage. Review the current access page or


101* iPhone on iOS 18 or later102* iPhone on iOS 18 or later

102* Android 9 or later103* Android 9 or later

103 104 

104iPad is not supported at initial launch.105The iOS app also runs on iPad with iPadOS 18 or later.

105 106 

106## What is the difference between a skill and a routine?107## What is the difference between a skill and a routine?

107 108 


120 121 

121## Can I share a Bot with someone else?122## Can I share a Bot with someone else?

122 123 

123Yes. Copy a public share link from the Bot. Anyone with the link can preview it124Yes. Choose **Share as template** from the Bot's actions, then **Copy link**,

124on [x.ai](https://x.ai) and add a copy to their account. They do not get your125and pick who can open it: **Public link** or **Team-only** (Enterprise accounts

126default to Team-only). Anyone who can open the link can preview it on

127[x.ai](https://x.ai) and add a copy to their account. They do not get your

125computer, logins, or conversation history.128computer, logins, or conversation history.

126 129 

127The link exposes the Bot's configuration. Strip secrets and anything130The link exposes the Bot's configuration. Strip secrets and anything

Details

36If the page is private, sign in through the computer or install the relevant36If the page is private, sign in through the computer or install the relevant

37connector.37connector.

38 38 

39Links in messages and results open in an in-app viewer when possible. Always39Links in messages and results open in your system browser; hovering over a

40check the destination before entering credentials or approving an external40link card shows a preview first. Always check the destination before entering

41action.41credentials or approving an external action.

42 42 

43## Ask for a reviewable result43## Ask for a reviewable result

44 44 

get-started.md +14 −7

Details

8 8 

9You need:9You need:

10 10 

11* An eligible plan: SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra,11* An eligible plan: every paid individual Cursor plan or the Cursor Teams plan,

12 or Cursor Teams Standard or Premium (sign in with your Cursor account)12 or an individual SuperGrok, SuperGrok Plus, or SuperGrok Heavy subscription

13 linked to your Cursor account (see

14 [Plans and billing](https://cursor.com/help/grok-bot/plans))

13* The Grok Bot desktop app for macOS, Windows, or Linux15* The Grok Bot desktop app for macOS, Windows, or Linux

14* An app or website where your first Bot can do useful work16* An app or website where your first Bot can do useful work

15 17 


59and `aarch64` means Arm64.61and `aarch64` means Arm64.

60 62 

61Grok Bot checks for updates automatically. You can also use **Check for63Grok Bot checks for updates automatically. You can also use **Check for

62Updates** from **Settings → Beta**.64Updates** from **Settings → Updates**.

63 65 

64## 2. Sign in66## 2. Sign in

65 67 

661. Choose **Get started** on the welcome screen. If you are already in the app,681. Choose **Sign in** on the welcome screen. If you are already in the app,

67 use **Sign In with Cursor** from Settings.69 use **Sign In with Cursor** from Settings.

682. Finish authentication in the browser window that opens.702. Finish authentication in the browser window that opens.

693. Return to Grok Bot after the browser confirms the sign-in.713. Return to Grok Bot after the browser confirms the sign-in.

724. If your access comes from a SuperGrok subscription, link it when the app

73 asks. On iPhone and Android, the access screen offers **Link Grok Account**

74 and then **Finished Linking? Refresh My Status**; on desktop,

75 **Settings → Usage & Billing** offers **Link SuperGrok Heavy** (the label

76 names the SuperGrok tier that applies to your account).

70 77 

71Grok Bot uses your Cursor account. If your organization requires single sign-on78Grok Bot uses your Cursor account. If your organization requires single sign-on

72(SSO), complete the normal organization sign-in flow.79(SSO), complete the normal organization sign-in flow.


95> Never change production settings.102> Never change production settings.

96 103 

97Focused Bots build more useful context than one catch-all Bot. You can add more104Focused Bots build more useful context than one catch-all Bot. You can add more

98Bots later with **New → Create new agent** when work naturally splits into105Bots later with **New → Create new Bot** when work naturally splits into

99distinct roles.106distinct roles.

100 107 

101## 4. Give it a first task108## 4. Give it a first task


139The browser session persists on your shared Grok Bot computer, so other Bots146The browser session persists on your shared Grok Bot computer, so other Bots

140can use the same signed-in session when appropriate.147can use the same signed-in session when appropriate.

141 148 

142For supported services, you can also install a connector from **Settings →149For supported services, you can also install a plugin from **Marketplace** in

143Plugins** and authenticate it in your browser.150the sidebar and authenticate it in your browser.

144 151 

145## 6. Review the result152## 6. Review the result

146 153 

mobile.md +17 −12

Details

12## Requirements12## Requirements

13 13 

14* iPhone with iOS 18 or later, or a phone with Android 9 or later14* iPhone with iOS 18 or later, or a phone with Android 9 or later

15* An eligible plan: SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra,15* An eligible plan: every paid individual Cursor plan or the Cursor Teams plan,

16 or Cursor Teams Standard or Premium (sign in with your Cursor account)16 or an individual SuperGrok, SuperGrok Plus, or SuperGrok Heavy subscription

17 linked to your Cursor account (see

18 [Plans and billing](https://cursor.com/help/grok-bot/plans))

17* Internet connection19* Internet connection

18 20 

19Grok Bot is currently designed for phones, not iPad.21The iOS app also runs on iPad (iPadOS 18 or later).

20 22 

21Download Grok Bot from the23Download Grok Bot from the

22[App Store](https://apps.apple.com/app/id6794501026) on iPhone or24[App Store](https://apps.apple.com/app/id6794501026) on iPhone or


26## Sign in and set up28## Sign in and set up

27 29 

281. Open Grok Bot.301. Open Grok Bot.

292. Choose **Login with Cursor**.312. Choose **Log In or Sign Up**.

303. Complete Cursor authentication in the browser.323. Complete Cursor authentication in the browser.

314. Return to the app.334. Return to the app. If your access comes from a SuperGrok subscription,

34 choose **Link Grok Account** when the access screen asks, finish linking in

35 the browser, then choose **Finished Linking? Refresh My Status**.

32 36 

33New users can complete the first-run tour, choose a first Bot, and wait while37New users can complete the first-run tour, choose a first Bot, and wait while

34the shared computer is set up. Existing users go directly to their synced Bot38the shared computer is set up. Existing users go directly to their synced Bot


54 58 

55## Create Bots and groups59## Create Bots and groups

56 60 

57Use the **+** control on the home screen to choose **New Agent** or **New Group61Use the **+** control on the home screen to choose **New Bot** or **New Group

58Chat**. You can also edit a Bot profile, manage group members, pin or hide a62Chat**. You can also edit a Bot profile, manage group members, pin or hide a

59conversation, and delete a Bot.63conversation, and delete a Bot.

60 64 


72## Manage recurring work76## Manage recurring work

73 77 

74Open a Bot's profile to review its routines. You can inspect the schedule, next78Open a Bot's profile to review its routines. You can inspect the schedule, next

75run, and instruction, then use **Active** to pause or resume a routine.79run, instruction, and **Run history**, use **Active** to pause or resume a

80routine, and delete a routine from the profile.

76 81 

77Editing the schedule or instruction, viewing run history, testing, and deleting82Editing the schedule or instruction and testing a routine currently require the

78a routine currently require the desktop app.83desktop app.

79 84 

80## Search and review prior work85## Search and review prior work

81 86 

82Use search from the home screen to find conversations and available message,87Use search from the home screen to find results across **Messages**, **Bots**,

83file, link, or routine results. Conversation actions provide quick access to88**Group Chats**, **Files**, and **Routines**, or **All** at once. Conversation

84common controls such as pin and hide.89actions provide quick access to common controls such as pin and hide.

85 90 

86## Settings91## Settings

87 92 

overview.md +2 −2

Details

91### Which platforms are supported?91### Which platforms are supported?

92 92 

93The desktop app runs on macOS (Apple silicon and Intel), Windows (x64 and93The desktop app runs on macOS (Apple silicon and Intel), Windows (x64 and

94Arm64), and Linux (x64 and Arm64), and the mobile app runs on iPhone and94Arm64), and Linux (x64 and Arm64), and the mobile app runs on iPhone, iPad,

95Android. The computers Bots work on run in Cursor's cloud.95and Android. The computers Bots work on run in Cursor's cloud.

96 96 

97### How much does Grok Bot cost?97### How much does Grok Bot cost?

98 98 

security.md +17 −14

Details

20## Network policy20## Network policy

21 21 

22Network Controls is Enterprise only. Admins set a Grok Bot network policy from22Network Controls is Enterprise only. Admins set a Grok Bot network policy from

23the Grok Bot page of the [Cursor dashboard](https://cursor.com/dashboard/bot).23the Grok Bot page of the [Cursor dashboard](https://cursor.com/dashboard/bot),

24under **Network** as **Grok Bot Network Access**.

24It controls which destinations team computers can reach. Self-serve Teams do25It controls which destinations team computers can reach. Self-serve Teams do

25not see this panel and cannot set a destination allowlist. Teams without a26not see this panel and cannot set a destination allowlist. Teams without a

26policy default to allow-all.27policy default to allow-all.

27 28 

28| Mode | Effect |29| Mode | Effect |

29| --- | --- |30| --- | --- |

30| No policy | Allow all (the default for teams without a policy) |31| **No Policy (Allow All)** | Allow all (the default for teams without a policy) |

31| Allow all network access | Explicitly allow all destinations |32| **Allow All Network Access** | Explicitly allow all destinations |

32| Defaults plus team allowlist | Cursor's default destinations plus your list |33| **Defaults + Team Allowlist** | Cursor's default destinations plus your list |

33| Team allowlist only | Only your list, plus the destinations a computer needs to function |34| **Team Allowlist Only** | Only your list, plus the destinations a computer needs to function |

34 35 

35* Destinations cover web domains as well as IP ranges with ports for raw36* Destinations cover web domains as well as IP ranges with ports for raw

36 connections, with no cap on the number of entries.37 connections, with no cap on the number of entries.


79When an action needs approval, the conversation shows the proposed operation80When an action needs approval, the conversation shows the proposed operation

80and its inputs. **Allow once** lets the Bot continue with that action,81and its inputs. **Allow once** lets the Bot continue with that action,

81**Always allow** can save a matching rule, and **Deny** blocks it (on iPhone82**Always allow** can save a matching rule, and **Deny** blocks it (on iPhone

82and Android, the controls are **Approve once** and **Deny**). An approval83and Android, the Auto-review sheet offers **Allow**, **Deny**, and, when a rule

84is proposed, **Always allow**). An approval

83controls the proposed action, not work already completed, and nobody should85controls the proposed action, not work already completed, and nobody should

84approve an action whose target or effect they cannot identify.86approve an action whose target or effect they cannot identify.

85 87 


99 edits, or deletes a rule. If admins turn enforcement off, the team rules stop101 edits, or deletes a rule. If admins turn enforcement off, the team rules stop

100 applying and members go back to their own rules only. See102 applying and members go back to their own rules only. See

101 [Auto-review rules](/grok-bot/teams-and-enterprises#auto-review-rules).103 [Auto-review rules](/grok-bot/teams-and-enterprises#auto-review-rules).

102* Members can add personal rules under **Settings → General → Auto-review**.104* Members can add personal rules under **Settings → General → Bot →

103 **Ask first** rules always stop matching actions, and **Allow105 Auto-review**. **Ask first** rules always stop matching actions, and **Allow

104 automatically** rules let matching actions proceed only when the reviewer106 automatically** rules let matching actions proceed only when the reviewer

105 finds no other reason to stop. Personal rules sit on top of team rules but107 finds no other reason to stop. Personal rules sit on top of team rules but

106 only make behavior stricter; **Ask first** wins when rules conflict. Narrow108 only make behavior stricter; **Ask first** wins when rules conflict. Narrow

107 rules around a known action and scope work best, like "ask first before109 rules around a known action and scope work best, like "ask first before

108 sending any external email" or "allow automatically when running110 sending any external email" or "allow automatically when running

109 `git status` in `/workspace/reports`"; avoid broad rules like "allow111 `git status` in `/workspace/reports`"; avoid broad rules like "allow

110 everything in the browser". Personal rules are stored on the current desktop112 everything in the browser". Personal rules are saved to the member's account

111 and synced to its Grok Bot computer, so another desktop installation needs113 and applied on every desktop they sign in to.

112 its own.

113* It does not review every side effect; memory writes and most settings changes114* It does not review every side effect; memory writes and most settings changes

114 are examples. Treat it as a complement to explicit boundaries and least115 are examples. Treat it as a complement to explicit boundaries and least

115 privilege, working alongside controls that do not depend on a model's116 privilege, working alongside controls that do not depend on a model's


254 255 

255Per-command approval is the default, and the approval card shows the exact256Per-command approval is the default, and the approval card shows the exact

256command. Members choose the policy under257command. Members choose the policy under

257**Settings → General → Agent → Execution on Local Computer**: ask every time,258**Settings → General → Bot → Execution on Local Computer** (or per computer

258always allow, or never. Recommend **Never** unless a Bot has a specific reason259under **Settings → Computer → Computers**): **Ask every time**, **Always

259to work on local files. Admins can cap the policy for the whole team with260allow**, or **Never allow**. Recommend **Never allow** unless a Bot has a

261specific reason to work on local files. Admins can cap the policy for the

262whole team with

260[Execution on Local Computer](/grok-bot/teams-and-enterprises#execution-on-local-computer)263[Execution on Local Computer](/grok-bot/teams-and-enterprises#execution-on-local-computer)

261on the Grok Bot page; a member's own setting still applies when it is264on the Grok Bot page; a member's own setting still applies when it is

262stricter. For the member-facing steps, see265stricter. For the member-facing steps, see

Details

17### Account17### Account

18 18 

19Sign in or out of the Cursor account used by Grok Bot. The account menu also19Sign in or out of the Cursor account used by Grok Bot. The account menu also

20shows **About**, the installed Grok Bot version, and a link to the iOS or20shows **About**, the installed Grok Bot version, and **Get Grok Bot for

21Android app.21mobile**, which opens the App Store listing.

22 22 

23### Appearance23### Appearance

24 24 

25Choose **Follow System**, **Light**, or **Dark**.25Choose **Follow System**, **Light**, or **Dark**.

26 26 

27### Agent27### Bot

28 28 

29Configure shared and local Bot behavior:29Configure shared and local Bot behavior:

30 30 


46rules with `Required by your admin. You can't edit or delete this rule.` You46rules with `Required by your admin. You can't edit or delete this rule.` You

47can add your own rules on top, but they only make behavior stricter; **Ask47can add your own rules on top, but they only make behavior stricter; **Ask

48first** wins when rules conflict. If your admin turns enforcement off, you only48first** wins when rules conflict. If your admin turns enforcement off, you only

49see and use your own rules. Your personal rules are stored on the current49see and use your own rules. Your personal rules are saved to your account and

50desktop and synced to its Grok Bot computer. Either way, do not assume another50apply on every desktop you sign in to. Read

51desktop installation carries the same configuration. Read

52[Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)51[Approvals, security, and privacy](/grok-bot/approvals-security-and-privacy)

53before changing either.52before changing either.

54 53 


71 70 

72## Plugins71## Plugins

73 72 

74Use **Marketplace** to discover plugins and packaged skills. Use **Yours** to73Plugins are not a settings section. Open **Marketplace** from the sidebar to

75review installed plugins and private skills.74discover plugins and packaged skills. To review what you have installed, choose

75**Your plugins** in Marketplace; **Manage plugins and skills** lists your

76**Installed** plugins and your **Private skills**.

76 77 

77An installed plugin may still need browser authentication. Individual plugin78An installed plugin may still need browser authentication. Individual plugin

78tools can be enabled or disabled. On the Teams plan and the Enterprise plan,79tools can be enabled or disabled. On the Teams plan and the Enterprise plan,


91For how plans, weekly usage, and on-demand spend work, see92For how plans, weekly usage, and on-demand spend work, see

92[Plans and billing](https://cursor.com/help/grok-bot/plans).93[Plans and billing](https://cursor.com/help/grok-bot/plans).

93 94 

94## Team Setup95## Updates

95 96 

96Team Setup is Enterprise only. When an Enterprise admin provides a managed97The update controls live in **Settings → Updates**. The Grok Bot app and Grok

97setup, **Team Setup** shows it here so you can review or reinstall the current98Bot's computer update separately:

98setup. Admins configure manifests from the dashboard; see

99[Grok Bot for teams and enterprises](/grok-bot/teams-and-enterprises#team-setup).

100 99 

101Do not place secret values directly in managed setup instructions.100* **Grok Bot Updates** shows the installed version. **Check for Updates** and

102 101 **Restart to Update** update the desktop app.

103## Beta and updates102* Under **Grok Bot's Computer**, **Update** installs the latest software on the

104 103 cloud computer and keeps your files in place.

105The update controls live in the **Beta** section of settings, alongside104* **Reset** wipes the computer and rebuilds it from your last saved snapshot, so

106security-key or egress-routing options when those are available. The Grok Bot105 very recent changes may be lost. Use it as a last resort.

107app and the Agent Computer update separately:

108 

109* **Check for Updates** and **Restart to Update** update the desktop app.

110* **Update Agent Computer** rebuilds the cloud computer on the latest image

111 while preserving durable state.

112* **Reset Agent Computer** is a last resort that returns the computer to its

113 synced durable state; unsynced recent work does not come back.

114 106 

115See [Troubleshooting](/grok-bot/troubleshooting) for the least destructive107See [Troubleshooting](/grok-bot/troubleshooting) for the least destructive

116recovery order.108recovery order.

117 109 

118## Edit one Bot110## Edit one Bot

119 111 

120Open **View conversation details**, then **Agent settings**, to edit that Bot's:112Open **View conversation details**, then **Bot settings**, to edit that Bot's:

121 113 

122* Name, title, and description114* **Name**, **Label (optional)**, and **Description**

123* Avatar115* Avatar

124* **Notifications** preference116* **Notifications** preference

125 117 

126These settings belong to one Bot. **Execution on Local Computer** and118These settings belong to one Bot. **Execution on Local Computer** is set per

127Auto-review settings are shared across Bots using the current setup, but are not119computer, and your Auto-review rules are saved to your account and apply on

128an account-synchronized policy across every device.120every desktop you sign in to.

129 121 

130## Understand attention states122## Understand attention states

131 123 

Details

335. What to return335. What to return

346. What requires approval346. What requires approval

35 35 

36Use **Settings → Plugins** to discover and install supported connectors and36Use **Marketplace** in the sidebar to discover and install supported connectors

37packaged skills. Type `/` in the desktop composer to reference a saved skill;37and packaged skills. Type `/` in the desktop composer to reference a saved skill;

38use `@` for Bots, groups, routines, and connectors.38use `@` for Bots, groups, routines, and connectors.

39 39 

40Installed private skills can be enabled per Bot. If a skill does not appear in40Private skills are one library shared by all your Bots. If a skill does not

41the `/` menu, open it under **Settings → Plugins → Yours** and enable it for the41appear in the `/` menu, open **Marketplace → Your plugins → Manage plugins and

42current Bot.42skills** and check that it is listed under **Private skills**.

43 43 

44## Teach a workflow by demonstration44## Teach a workflow by demonstration

45 45 

Details

138 138 

139#### Enable Grok Bot139#### Enable Grok Bot

140 140 

141The organization-wide switch on the Grok Bot page, with **Manage Group Access**141The organization-wide switch on the Grok Bot page, labeled **Enable Grok Bot

142beside it. Turning it on opens a setup modal that covers privacy mode, pricing,142for your team**, with **Manage Group Access** beside it. A team that has never

143and model availability. Turning it off blocks every member without deleting143set up Grok Bot sees a **Set Up Grok Bot** call to action with an **Open Docs**

144their computers. See144link instead; on Enterprise it opens a setup modal that covers privacy mode,

145pricing, and model availability. Turning the switch off opens a **Disable Grok

146Bot** confirmation and then blocks every member without deleting their

147computers. On the Teams plan the same card is a status line, **Grok Bot is

148enabled for your team**, with no switch. See

145[Enabling Grok Bot for your team](#enabling-grok-bot-for-your-team).149[Enabling Grok Bot for your team](#enabling-grok-bot-for-your-team).

146 150 

147Available on the Enterprise plan.151Available on the Enterprise plan.


252 256 

253#### Network Controls257#### Network Controls

254 258 

255Restricts which destinations team computers can reach. Pick one of four modes,259Restricts which destinations team computers can reach. On the dashboard the

256from allow-all to a team allowlist of domains and IP ranges. Directory groups260section is **Network** and the control is **Grok Bot Network Access**. Pick one

257can carry their own policy, and a lock makes the team policy apply to everyone.261of four modes, from allow-all to a team allowlist of domains and IP ranges:

258Teams without a policy default to allow-all. See262**No Policy (Allow All)**, **Allow All Network Access**, **Defaults + Team

263Allowlist**, or **Team Allowlist Only**. Directory groups can carry their own

264policy as **Group Network Access**, and **Lock for all groups** makes the team

265policy apply to everyone. Teams without a policy default to allow-all. See

259[network policy](/grok-bot/security#network-policy) for the modes and how a266[network policy](/grok-bot/security#network-policy) for the modes and how a

260new policy reaches running computers.267new policy reaches running computers.

261 268 


265 272 

266Manifests of install scripts that run on every team computer, so the same273Manifests of install scripts that run on every team computer, so the same

267tooling is present everywhere. Keep secret values out of setup scripts. Members274tooling is present everywhere. Keep secret values out of setup scripts. Members

268see the managed setup under275do not see or manage the setup in the app; scripts run on their computer when

269[Team Setup](/grok-bot/settings-and-notifications#team-setup) in the app,276it starts and on a periodic refresh. For how manifests run, and to install a

270where they can review or reinstall it. For how manifests run, and to install a

271networking client that reaches private services, see277networking client that reaches private services, see

272[Connect to private networks](/grok-bot/private-networks).278[Connect to private networks](/grok-bot/private-networks).

273 279 

troubleshooting.md +24 −18

Details

301. Retry from the error state.301. Retry from the error state.

312. Restart Grok Bot.312. Restart Grok Bot.

323. Check for a Grok Bot app update.323. Check for a Grok Bot app update.

334. Use **Update Agent Computer** if the computer remains unreachable.334. If the computer remains unreachable, open **Settings → Updates** and choose

34 **Update** under **Grok Bot's Computer**.

34 35 

35## The computer cannot be reached36## The computer cannot be reached

36 37 


41 42 

421. Choose **Retry** or reopen the conversation.431. Choose **Retry** or reopen the conversation.

432. Restart the Grok Bot app.442. Restart the Grok Bot app.

443. Choose **Recover computer** or **Recover Agent Computer** from the453. Choose **Recover computer** from the unreachable-computer state when offered

45 unreachable-computer state when offered.46 (the confirmation dialog calls it **Recover Grok Bot's Computer**).

464. If recovery is not available, open **Settings → Beta** and choose **Update474. If recovery is not available, open **Settings → Updates** and choose

47 Agent Computer**.48 **Update** under **Grok Bot's Computer**. On iPhone and Android, the same

49 controls are **Update Computer** and **Reset Computer** under **Settings →

50 Bot → Bot Computer**.

485. Wait for the replacement computer to become available.515. Wait for the replacement computer to become available.

496. Use **Reset Agent Computer** only if recovery and update fail and you accept losing526. Use **Reset** only if recovery and update fail and you accept losing recent

50 recent unsynced work.53 unsynced work.

51 54 

52**Recover Agent Computer** and **Update Agent Computer** preserve durable files55**Recover computer** and **Update** preserve durable files and logins.

53and logins. **Reset Agent Computer** restores the last saved snapshot and can56**Reset** restores the last saved snapshot and can lose recent or unsynced

54lose recent or unsynced work.57work.

55 58 

56## A Bot appears stuck59## A Bot appears stuck

57 60 


81 84 

82## A plugin will not install or authenticate85## A plugin will not install or authenticate

83 86 

841. Open **Settings → Plugins** and confirm the connector is installed.871. Open **Marketplace** from the sidebar, choose **Your plugins**, and confirm

88 the plugin is listed under **Installed**.

852. Reopen its detail page and choose the authentication action.892. Reopen its detail page and choose the authentication action.

863. Complete authorization with the intended account in the browser.903. Complete authorization with the intended account in the browser.

874. Return to Grok Bot and retry the task.914. Return to Grok Bot and retry the task.


1302. Send the Bot a replacement instruction1342. Send the Bot a replacement instruction

1313. Ask it to regenerate the action with the corrected scope1353. Ask it to regenerate the action with the corrected scope

132 136 

133If an action keeps requiring approval, check **Settings → General →137If an action keeps requiring approval, check **Settings → General → Bot →

134Auto-review** for a matching **Ask first** rule, including team rules your138Auto-review** for a matching **Ask first** rule, including team rules your

135admin requires. **Ask first** rules take precedence over **Allow139admin requires. **Ask first** rules take precedence over **Allow

136automatically** rules.140automatically** rules.


138## Local computer work is refused142## Local computer work is refused

139 143 

140Cloud-computer work and local-computer work use different permissions. Open144Cloud-computer work and local-computer work use different permissions. Open

141**Settings → General → Agent → Execution on Local Computer** and review the145**Settings → General → Bot → Execution on Local Computer** (or the computer's

142policy.146row under **Settings → Computer → Computers**) and review the policy.

143 147 

144Keep local access disabled unless the task specifically requires files or148Keep local access disabled unless the task specifically requires files or

145commands on the computer in front of you.149commands on the computer in front of you.


148 152 

149The Grok Bot app and the Agent Computer have separate updates.153The Grok Bot app and the Agent Computer have separate updates.

150 154 

151* To update the app, open **Settings → Beta → Check for Updates**. If an update155* To update the app, open **Settings → Updates → Check for Updates**. If an

152 is ready, choose **Restart to Update**.156 update is ready, choose **Restart to Update**.

153* To rebuild the cloud computer, use **Update Agent Computer**.157* To rebuild the cloud computer, choose **Update** under **Grok Bot's

158 Computer** in the same section.

154 159 

155Updating the desktop app does not reset the cloud computer.160Updating the desktop app does not reset the cloud computer.

156 161 


164* The Bot or routine name169* The Bot or routine name

165* The approximate time and time zone170* The approximate time and time zone

166* The full request ID or conversation ID if one is shown171* The full request ID or conversation ID if one is shown

167* Whether retry, app restart, or **Update Agent Computer** changed the result172* Whether retry, app restart, or updating Grok Bot's computer changed the

173 result

168 174 

169Do not include passwords, one-time codes, private keys, or secret values.175Do not include passwords, one-time codes, private keys, or secret values.