34 34
35* On desktop, **Allow once** lets the Bot continue with that action and35* On desktop, **Allow once** lets the Bot continue with that action and
36 **Deny** blocks it. **Always allow** can save a matching rule.36 **Deny** blocks it. **Always allow** can save a matching rule.
3737* On iPhone and Android, the equivalent controls are **Approve once** and* On iPhone and Android, the Auto-review sheet offers **Allow**, **Deny**, and,
3838 **Deny**. when a rule is proposed, **Always allow**; a local-command card offers
39 **Allow once** and **Deny**.
39 40
40Do not approve an action whose target or effect you cannot identify. Ask the Bot41Do not approve an action whose target or effect you cannot identify. Ask the Bot
41to explain it in plain language or produce a draft first.42to explain it in plain language or produce a draft first.
43## Configure Auto Review44## Configure Auto Review
44 45
45With Auto Review on, Grok Bot evaluates tool calls and computer actions before46With Auto Review on, Grok Bot evaluates tool calls and computer actions before
4647they run. Open **Settings → General → Auto-review** to add rules.they run. Open **Settings → General → Bot → Auto-review** to add rules.
47 48
48* **Ask first** rules always stop matching actions for you.49* **Ask first** rules always stop matching actions for you.
49* **Allow automatically** rules let matching actions proceed only when the50* **Allow automatically** rules let matching actions proceed only when the
65behavior change over time. Auto Review is model-based and should complement,66behavior change over time. Auto Review is model-based and should complement,
66not replace, least privilege and explicit approval boundaries.67not replace, least privilege and explicit approval boundaries.
67 68
6869Personal Auto-review rules are stored on the current desktop and synced to itsPersonal Auto-review rules are saved to your account and applied on every
6970Grok Bot computer. Verify them separately on another desktop installation.desktop you sign in to, as well as on your Grok Bot computer.
70 71
71## Enter passwords and verification codes yourself72## Enter passwords and verification codes yourself
72 73
84the value in that request. It is not a general-purpose password manager. The85the value in that request. It is not a general-purpose password manager. The
85value is masked, excluded from the transcript, and not shown to the model.86value is masked, excluded from the transcript, and not shown to the model.
86 87
88When a web page needs you to type something yourself, such as a login, a
89checkout address, or a phone number, the Bot can show a form in the chat, one
90form per step, and fill your answers into the page for you.
91
92If you sign in with a hardware security key, such as a YubiKey, the Bot's
93browser can use a key plugged into your desktop while **Use hardware security
94keys** is on under **Settings → General → Security Key**. The setting is on by
95default on macOS and Windows and is not yet supported on Linux; every use asks
96you to approve it first.
97
87## Control access to your local computer98## Control access to your local computer
88 99
89The shared Grok Bot computer runs in the cloud. Access to the Mac or Windows100The shared Grok Bot computer runs in the cloud. Access to the Mac or Windows
90computer in front of you is a separate capability.101computer in front of you is a separate capability.
91 102
92103In **Settings → General → Agent → Execution on Local Computer**, choose whetherIn **Settings → General → Bot → Execution on Local Computer**, choose
93104local commands:**Ask every time**, **Always allow**, or **Never allow**. Once your account has
105registered computers, the choice moves to **Settings → Computer → Computers**,
106where each computer has its own **Execution on this computer** setting.
94 107
95108* Always require approvalThe default is **Ask every time**. Use **Never allow** unless a Bot has a
96* Are always allowed
97* Are never allowed
98
99The default is **Ask every time**. Use **Never allowed** unless a Bot has a
100specific reason to work on your local files. Your team admin can cap this109specific reason to work on your local files. Your team admin can cap this
101setting for the whole team; when the team's policy is stricter than yours, the110setting for the whole team; when the team's policy is stricter than yours, the
102team's applies. These settings do not prevent the Bot from using its cloud111team's applies. These settings do not prevent the Bot from using its cloud
103computer.112computer.
104 113
114The first time a Bot asks to run a command on your computer, the conversation
115shows **Allow Grok Bot and all Bots to run commands on your local computer?**
116with **Always allow**, **Allow once**, **Never**, and **Deny once** (Esc).
117**Always allow** and **Never** set **Execution on Local Computer** for every
118Bot, and you can change the setting later in Settings. If your team's admin has
119set a stricter ceiling, **Always allow** is unavailable.
120
105## Understand the shared-computer boundary121## Understand the shared-computer boundary
106 122
107All of your Bots share one cloud computer assigned to your user account. Files,123All of your Bots share one cloud computer assigned to your user account. Files,