Take an invented example. You set up one Bot to handle expenses and a second to do web research. It is natural to assume the research Bot cannot use the bank website the expenses Bot is signed in to. Under the rule in Grok Bot’s own documentation, it can.
Each Bot has its own role, conversation and screen. All of your Bots share one cloud computer, with its files, browser sessions and logins. The FAQ says so in two sentences: “The computer is assigned per user, not per Bot. Do not use separate Bots as a security boundary.” [1]
The documentation is open about this and gives the reason: the Bots share all of that “so they can hand work off.” [1] What follows is the arrangement as the documentation described it on 30 September 2026, and what it means when you set up a second Bot.
What is separate and what is shared
| What | Who has it | What the documentation says |
|---|---|---|
| Role, conversation and what the Bot has learned about its job | Each Bot | “Its conversation and learned role are separate from other Bots” [1] |
| Screen | Each Bot | “Each Bot gets its own screen on the shared computer.” The screens are “separate work surfaces, not separate security boundaries.” [2] |
| Routines (work that runs on a schedule or after an event) | One Bot each | “A routine assigns a workflow to one Bot” [1] |
| Files | All your Bots | “Files are visible to every Bot” [2] |
| Browser cookies and signed-in websites | All your Bots | “Browser cookies and signed-in sessions are shared” [2] |
| Command-line credentials | All your Bots | “Command-line credentials are shared” [2] |
| Connectors (installed links to other services) | All your Bots | “Installed connectors are account-wide. Their availability is not isolated to one Bot.” [2] |
| Private skills (saved instructions for a task) | All your Bots | “Private skills are one library shared by all your Bots.” [3] |
| The cloud computer itself | One per user | “One user cannot reach another user’s computer.” [4] |
Even the per-Bot rows are not sealed off. The FAQ adds that “shared files, browser sessions, group messages, and direct handoffs can move context between them.” [1]
For logins, the documentation spells out the consequence: “Because the browser is shared, signing in for one Bot makes the session available to your other Bots.” [2] In the example above, signing in to the bank’s website for the expenses Bot leaves that session available to the research Bot as well.
The advice that goes with it: “Do not place a credential or file on it if another Bot on your account should not be able to use it.” [2] For work that has to be kept apart, the security FAQ names the remedy: “When a workload needs its own computer and credential set, give it its own Cursor user.” [4]
What a Bot remembers
The FAQ’s answer is short: “A Bot can retain stable preferences, role context, and summaries of prior work.” [1] The documentation does not ask you to treat that memory as a record. “For important decisions, ask the Bot to check the current source rather than relying on memory.” [1] The page on managing Bots adds that changing facts should be kept in the system they come from, that you should correct stale assumptions directly, and that safety boundaries belong in the Bot’s description. Its example of a description rule is “Never send external messages without approval.” [5]
We did not find a screen for viewing what a personal Bot has remembered, or a way to delete a single remembered item, documented in the pages we read. What those pages do describe is correcting the Bot directly and editing its description. [5]
Deleting a Bot does not clean the shared computer
The FAQ says: “Deletion removes the Bot’s active profile, conversation, and routines from Grok Bot. Because Bots share a computer, files and logins on that computer may remain.” [1] The approvals page is blunter: “Deleting a Bot does not remove shared-computer files or browser sessions.” [6]
The pages we read do not say what happens to a deleted Bot’s stored memory beyond that. On retention they point elsewhere: “Backend retention follows the applicable Cursor terms.” [1] We did not read those terms.
For a project or login that should no longer be available, the approvals page gives a list. Its first four steps [6]:
- Pause or delete the routines involved.
- Sign out of the websites on the shared computer.
- Uninstall the connectors, and revoke their authorization in the service they connect to.
- Remove sensitive project files from
/workspace, the shared folder.
Hiding a Bot only takes it out of the sidebar: “Hiding does not pause the Bot or its routines.” [5] Resetting the computer is for recovery: Reset “rebuilds the computer from your last saved snapshot”. [2]
As for the account, Cursor’s help page says: “Grok Bot does not have a separate account. Delete the Cursor account you use to sign in.” It lists Grok Bot agents, chats, computers and connected plugins among what is deleted, and says “All data is removed within 30 days.” [7]
Who runs it
You sign in with a Cursor account; Cursor’s help page says “There is no separate Grok Bot login.” [8] The overview says “The computers Bots work on run in Cursor’s cloud” [9], and the security page says “Grok Bot computers run in the United States today.” [10] The documentation itself is published at docs.x.ai under the name SpaceXAI Docs. [6]
Approvals, briefly
Auto Review is a setting you can turn off, unless an Enterprise admin has locked it on; that lock is off by default. [11] “With Auto Review on, Grok Bot evaluates tool calls and computer actions before they run.” [6] The reviewer is a model, and the documentation says it “should complement, not replace, least privilege and explicit approval boundaries.” [6] You can add rules of two kinds, “Ask first” and “Allow automatically”, and “If both kinds of rule match, Ask first wins.” [6] Letting a Bot work on the Mac or Windows computer in front of you is a separate setting, and “The default is Ask every time.” [6] Our piece on what an AI agent may read and what it may do covers approvals in more detail.
Privacy settings and training
Grok Bot uses your Cursor account’s data settings, and one of them rules it out: “Grok Bot requires data storage and does not support Legacy Privacy Mode.” [6] That is the legacy setting only. The security page, in a passage about teams, says “Privacy Mode applies” and that “with Privacy Mode enabled, customer data is not used for training.” [10]
On training, the approvals page says only this: “Training opt-out follows the applicable Cursor account and privacy settings.” [6] The pages we read do not state what happens when Privacy Mode is off. They refer readers to Cursor’s Privacy Policy for the detail, and we did not open it. [6]
Access and platforms
Cursor’s plans page says you do not need a separate Grok Bot subscription. [12] The FAQ says “Grok Bot is included with every paid individual Cursor plan and with the Cursor Teams plan, and you can link an individual SuperGrok, SuperGrok Plus, or SuperGrok Heavy subscription.” [1] Cursor’s page also lists an X Premium+ account link [12]; the docs.x.ai pages we read do not mention it.
On platforms the official pages differ. The FAQ, last updated 29 September 2026, says: “Use the Grok Bot desktop app on macOS, Windows, or Linux, or the companion app on iOS or Android.” [1] The product page, which shows no date, says: “Work with Grok Bot from your desktop (macOS or Windows) or your phone with the iOS app.” [13] The launch post of 11 August 2026 says “on desktop and iOS”. [14]
Before you give a second Bot a different job
- Assume that anything one Bot can open, the others can: files, signed-in websites, command-line credentials and connectors.
- Keep a sensitive login off the shared browser unless every Bot should have it. If one job needs logins the others must never use, the documented answer is a separate Cursor user. [4]
- Write each Bot’s standing rules into its description.
- Decide which actions should be Ask first. The FAQ suggests “narrow Ask first rules for actions such as sending, publishing, deleting, purchasing, or changing production systems.” [1]
- For access to your own computer, the documentation’s advice is stricter than the default: “Use Never allow unless a Bot has a specific reason to work on your local files.” [6]
- When a job ends, work through the clean-up steps yourself. Deleting the Bot removes its routines and leaves the files and logins.
How we checked
On 30 September 2026 we read the Grok Bot documentation at docs.x.ai, the launch post and product page on x.ai, and Cursor’s help pages for Grok Bot. We did not install, operate or test Grok Bot, so this article reports what those pages say.
The pages differ in three places. Two are covered above: the platform lists, and X Premium+, which Cursor’s page lists and the docs.x.ai pages we read do not mention. On Enterprise access the launch post mentions “a waitlist” [14] and the product page says “generally available” [13], so we have left Enterprise out.
Kluro, which publishes this article, makes a Mac app in the same broad area. Grok Bot is not one of the sources Kluro connects to. Kluro’s pages, including how Kluro uses AI, describe finding, remembering and preparing; they do not describe Kluro sending messages or acting in other apps for you.
Sources
- Frequently asked questions — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- Use the computer and apps — SpaceXAI Docs. Updated 14 September 2026. Checked 30 September 2026.
- Skills and routines — SpaceXAI Docs. Updated 14 September 2026. Checked 30 September 2026.
- Grok Bot security FAQ — SpaceXAI Docs. Updated 28 September 2026. Checked 30 September 2026.
- Create and manage Bots — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- Approvals, security, and privacy — SpaceXAI Docs. Updated 28 September 2026. Checked 30 September 2026.
- Delete your Grok Bot account — Cursor Docs. Living documentation. Checked 30 September 2026.
- Sign in to Grok Bot — Cursor Docs. Living documentation. Checked 30 September 2026.
- Grok Bot (overview) — SpaceXAI Docs. Updated 21 September 2026. Checked 30 September 2026.
- Grok Bot security — SpaceXAI Docs. Updated 28 September 2026. Checked 30 September 2026.
- Grok Bot for teams and enterprises — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- Plans and billing — Cursor Docs. Living documentation. Checked 30 September 2026.
- AI teammates that finish the work | Grok Bot — SpaceXAI. Living documentation. Checked 30 September 2026.
- Introducing Grok Bot — SpaceXAI. Published 11 August 2026. Checked 30 September 2026.
