# What Is Grok Bot? SpaceXAI's Always-On AI Teammates, Explained

> Grok Bot is SpaceXAI's app for persistent AI teammates that share one cloud computer, sign in to your tools, and act as you. Here is how it works, what it costs, and what to lock down before you hand it your logins.

*10 min read · Published 2026-09-14 · [Muhammad Idrees](https://adrees.dev/about)*

Grok Bot is not a better chatbot. It is a staff of persistent AI teammates that share one cloud computer, keep working after you close the laptop, and sign in to your tools as you. That design is why early testers came away enthusiastic, and it is also why the terms make you responsible for everything a Bot does. Both things are true at once, and anyone deploying it has to plan for both.

## Key takeaways
- Grok Bot is SpaceXAI's app for persistent AI teammates, launched in beta on August 11, 2026. Each Bot has a name, a job, and its own conversation and memory, and all of a user's Bots work on one shared, persistent cloud computer with a browser, a filesystem, and a terminal.
- Grok Bot is not the Grok chatbot on grok.com or in the Grok apps, and it is not @grok, the reply account on X. It is a separate product that uses Cursor sign-in, runs on Cursor-hosted computers in the United States, and relies on models Cursor selects, with no customer-facing model picker.
- As of September 2026, Grok Bot has no separate subscription: it comes with Cursor Pro ($20 a month), Pro+ ($60), Ultra ($200), or Cursor Teams ($40 or $120 per user a month), or with a linked individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+ subscription. Weekly allowances are described only in words, with no numbers published, and on-demand usage beyond them, if enabled, is billed through Cursor with no Grok Bot-specific spend cap.
- All of a user's Grok Bots share the same files, browser sessions, and logins, and the Grok Bot docs say not to use separate Bots as a security boundary. Bots act as the signed-in user, sign in to sites by having that user take over the computer for the sensitive step, and keep connector OAuth tokens on Cursor's backend rather than on the computer.
- Cursor's Grok Bot Terms, updated September 3, 2026, make the customer solely responsible for every action Grok Bot takes and describe approval and review controls as aids only. Before real use, set Execution on Local Computer to Never unless a Bot needs your local files, add Require Approval (Ask first) rules for sending, deleting, purchasing, and production changes, and budget every routine run and bot-to-bot message as usage.

## What Grok Bot actually is, and what it is not
Grok Bot is SpaceXAI's app for what it calls "your team of always-on agents", launched on August 11, 2026. SpaceXAI's August posts called it a beta, and whether that label still applies is not documented. A Bot is a durable AI teammate with a name, a job, and its own conversation and memory, working on a persistent cloud computer with a browser, a filesystem, and a terminal. Closing the desktop or phone app does not stop the work.

The name causes real confusion. Grok Bot is not Grok, the chatbot on grok.com and in the Grok apps, and SpaceXAI's own Grok FAQ says the two are not the same. Nor is it @grok, the account people tag on X for a public reply. The branding also hides the operator: Grok Bot runs on Cursor's sign-in, cloud, and billing. The short version: Grok is the chatbot, @grok is its reply account, and Grok Bot is a team of agents working inside your accounts.

## The vocabulary is the product
Read Grok Bot as a list of nouns, because the list is the product. A Bot has a name, a title for its job, and a description where lasting rules belong. It retains preferences, important facts, and summaries of past work, though the docs describe no screen for viewing or editing that memory. The computer is the most misunderstood noun. Some SpaceXAI posts say each Bot has a computer of its own, but the docs are explicit: all of a user's Bots share one persistent cloud computer, with its files, browser sessions, and command-line credentials. Each Bot gets its own screen, and screens are work surfaces, not security boundaries.

Signing in works by takeover. For a password, two-factor code, CAPTCHA, or payment step, the Bot asks you to take control of its computer, finish only that step, and hand control back. That session then persists for every other Bot; SpaceXAI's own Grok Bot 101 guide warns that a Bot on a computer logged into Amazon can technically buy whatever it wants. Connectors, called Plugins in the app, cover services such as Gmail, Google Calendar, Drive, Notion, and Slack; an installed plugin applies to every Bot on the account, and its OAuth tokens stay on Cursor's backend, never on the computer.

## Skills, routines, and the approval layer
The distinction operators most need is skills versus routines. A skill describes how to do a task and is available across your Bots. A routine assigns a workflow to one Bot and says when it runs: on a schedule, or on an event such as a Slack keyword, a GitHub notification, or a webhook. Each Bot can hold up to 50 routines, scheduled runs must be at least five minutes apart, and a test run performs real work. A feature called Teach a task records a browser workflow of up to ten minutes and produces a draft skill, not a finished automation.

Bots can also message each other directly. A Cursor staff member confirmed that each bot-to-bot message makes the receiving Bot take a turn of work that counts toward weekly usage, so a chatty team is an expensive one. Actions that need sign-off stop at an approval card showing the proposed operation. Behind the cards sits Auto Review, a separate review model that checks shell commands, plugin calls, computer use, routine changes, and handing coding tasks to Cursor Cloud Agents. It does not review memory writes, and approvals do not reverse work a Bot has already completed.

## What it costs, and why budgeting is hard
Grok Bot has no subscription of its own; usage is metered on your Cursor account. As of September 2026, access comes with Cursor Pro at $20 a month, Pro+ at $60, Ultra at $200, or Cursor Teams at $40 per user a month for Standard or $120 for Premium, which carries five times Standard's usage. You can instead link an individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+ subscription; the link is permanent, grants usage only while that subscription stays active, and does not stack with a Cursor plan. Launch-day access was limited to SuperGrok Heavy, Cursor Ultra, and Cursor Teams Premium, so coverage quoting a $120 starting price is out of date. Enterprise pricing is not published.

Weekly allowances are described only in words, with no numbers published: Ultra gets "Highest weekly usage", Pro+ "Generous weekly usage, below Ultra", and Pro sits below Pro+. When the weekly pool runs out, Grok Bot draws on-demand usage if you enabled it, billed through Cursor and priced from model and token cost, and otherwise stops until the weekly reset. There is no Grok Bot-specific spend cap, the monthly on-demand limit is not a hard stop mid-run, and on the Teams plan on-demand usage is on by default. The free trial is a usage credit with a seven-day window, and one large run can spend all of it.

Cursor's help pages warn that an hourly schedule or a Slack listener on a busy channel can use a week of usage in a day. One Ultra subscriber, Craig Hewitt, posted that his Grok Bot hit its weekly limit in one day. Even which allowance Grok Bot draws from is contested: SpaceXAI's August posts call its usage separate from your Grok and Cursor plans, and Cursor's help says a Teams seat draws from that seat's allowance. A Cursor staff member also wrote on September 3 that routines and browser actions were counting against the Cursor plan. Whether Grok Bot is expensive is impossible to say from the outside. What is clear is that its bill is hard to forecast.

## Strong architecture, loose defaults
Buying an agent means renting its security boundary, and Grok Bot's has real strengths. Each user's work runs in a dedicated Firecracker microVM in Cursor's cloud, with hardware-level separation from other users. Values saved in a Bot's Secrets section are write-only, and a secure secret card can fill a secret into a web page without the Bot ever seeing it. Apart from team-managed connectors, Bots have no identity of their own and never hold more access than the person they act for. Anysphere, the company behind Cursor, holds ISO/IEC 27001 and 42001 certifications with Grok Bot in scope.

The defaults are looser than the architecture. Deleting a Bot may leave the files and sign-ins it used behind on the shared computer, where every other Bot can still use them. Network policy is Enterprise-only, teams without one default to allow-all, and blocking a plugin does not block that service's website. Audit logs and Action Recording are Enterprise-only too, recording is off by default, and dedicated data loss prevention hooks are not available. On self-serve Cursor Teams, Grok Bot is enabled for every member with no switch to turn it off. The security docs say prompt injection defenses reduce the risk without eliminating it; plan around that.

We harden it the way the docs suggest. Set Execution on Local Computer to Never unless a Bot needs your local files. Require Approval rules (called Ask first in Cursor's newer docs) take precedence over Always Allow rules, so add narrow ones for sending, publishing, deleting, purchasing, and production changes, and prefer Allow once for anything touching accounts, money, or shared resources. Give any workload that needs separate credentials its own Cursor user. When a project or login should no longer be available, pause related routines, sign out of websites on the shared computer, uninstall connectors and revoke them at the source, and clear sensitive files from /workspace; deleting a Bot may not remove shared files or browser sessions. For departing members, Cursor's docs say terminating their computer does not remove access; removing the member and revoking identity-provider sessions does.

## Who you are actually trusting
The SpaceXAI name is on the app, but the machinery is Cursor's; even the Grok Bot docs on SpaceXAI's site mirror Cursor's documentation, and the two copies already disagree on some admin controls. Cursor also picks the model: there is no picker, no Grok Bot page names it, and the serving mix can change. OpenAI has announced it will end Cursor's access to its models on November 12, 2026, and whether that changes Grok Bot's serving mix is not documented. SpaceXAI and Cursor now both sit inside SpaceX, which bought xAI, the company behind Grok, in February 2026, brands its AI business SpaceXAI, and closed its acquisition of Cursor on August 14, 2026.

Cursor's Grok Bot Terms, updated September 3, 2026, make the customer solely responsible for every agentic action Grok Bot takes, whether or not it was intended or authorized, except loss directly caused by the provider's gross negligence or willful misconduct. They call approval and review controls aids only, and require human review before external communications, financial transactions, data deletion, permission changes, production system changes, and legal commitments. In our reading, that sits awkwardly beside Elon Musk's reply on August 26, 2026 to a user asking about connecting a bank account: "If Grok Bot messes up, we will make you whole." Treat that as a post, not a contract: the terms are what bind you.

Keep vendor risk in proportion. Cursor's status page logged Grok Bot connector delays, dropped routine triggers, and unreachable computers between August 18 and September 7, 2026, so build routines that tolerate a missed run. Through September 14, 2026, we found no disclosed vulnerability specific to Grok Bot.

## When we'd reach for it
We reach for Grok Bot when the work lives in browser tools and inboxes with no clean API, the client already pays for Cursor or SuperGrok, and the job suits a capable junior teammate: account research, CRM hygiene, or outreach drafted for approval. The hard part of an always-on agent is rarely the model; it is the plumbing of logins, schedules, and approvals, and Grok Bot ships that plumbing ready-made. SpaceXAI's own procurement write-up models the right pattern: its Bot needed explicit approval to spend money, accept terms, or send anything to vendors, and staff still revise its vendor emails. We start the same way, with one Bot, one skill tested by hand, approvals on anything that leaves the company, and a weekly look at usage before adding routines.

We hesitate on regulated data, on anything that moves money, and on workflows where an agent needs an auditable identity separate from a person's. Grok Bot is not on Cursor's public list of HIPAA-eligible services, its computers run in the United States today with no other region documented, and there is no on-premises option. If you want to own the runtime and tune the model, "What Is OpenClaw? The Local-First AI Agent, Explained" and "Hermes Agent, Explained for Operators" cover that end. The companion piece "Claude Managed Agents, Explained for Operators" covers a hosted platform you build on, and "AI Agents vs. Automation vs. an AI Operating System: Which Do You Need?" asks whether you need an agent at all. Grok Bot is the fully rented end of that spectrum: low setup, strong ergonomics, and every action still taken in your name.

## FAQ
**What is Grok Bot?**

Grok Bot is SpaceXAI's app for persistent AI teammates, called Bots, that do work on one shared cloud computer instead of only answering questions. Each Bot has a name, a job, and its own conversation and memory, and it can use a browser, files, a terminal, and connectors such as Gmail, Google Calendar, Notion, and Slack. Bots keep working when your laptop or phone is closed, can run on schedules or event triggers through routines, and can be set to stop for approval before sensitive steps. Grok Bot launched in beta on August 11, 2026, and Cursor operates the service, including sign-in, hosting, and billing.

**Is Grok Bot the same as Grok or @grok on X?**

No. Grok Bot is a separate product from Grok, the chatbot on grok.com and in the Grok mobile apps, and SpaceXAI's Grok FAQ says the two are not the same. It is also different from @grok, the account people mention in posts on X to get a public reply from Grok. Grok Bot is a desktop and mobile app that uses Cursor sign-in and runs AI teammates that work inside your accounts from one shared cloud computer. It can work with your X account through an X connector added on August 29, 2026, but that does not make it the reply account.

**How much does Grok Bot cost?**

Grok Bot has no separate subscription; as of September 2026 it is included with Cursor Pro at $20 a month, Pro+ at $60, Ultra at $200, or Cursor Teams at $40 (Standard) or $120 (Premium) per user a month. Access can also come from linking an individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+ subscription, and a linked subscription does not stack with a Cursor plan. Each plan includes weekly usage that is described only in words, with no numbers published. Beyond that allowance, on-demand usage, if enabled, is billed through Cursor and priced from model and token cost, with no Grok Bot-specific spend cap. Enterprise pricing is not published.

**Which AI model does Grok Bot use?**

No specific model is documented for Grok Bot. Cursor manages model selection, there is no customer-facing model picker, and the docs say the serving mix can change over time with no fixed vendor set guaranteed. Usage analytics show which model served each request, and billing follows that serving model. Enterprise teams can set a model allowlist, but the docs say its enforcement is not guaranteed.

**Is it safe to give Grok Bot my logins?**

It can be reasonable for low-stakes work if you configure it deliberately, but any login you give one Bot is available to all of your Bots, because they share one computer. Sign-ins happen by you taking over the cloud computer for the password or two-factor step, connector OAuth tokens stay on Cursor's backend, and values saved in a Bot's Secrets section are write-only. The docs say separate Bots are not a security boundary, deleting a Bot may leave logins on the computer, and prompt injection controls reduce but do not eliminate risk. Cursor's Grok Bot Terms also make you responsible for every action a Bot takes, so add Require Approval (Ask first) rules for sending, purchasing, deleting, and production changes, and keep high-stakes accounts off it.

**Does each Grok Bot have its own computer?**

No. Although some SpaceXAI posts describe each Bot as having a computer of its own, the Grok Bot docs and FAQ say every Bot on your account uses one persistent cloud computer, assigned per user rather than per Bot. Bots share its files, browser sessions, and logins so they can hand work off, and each Bot gets its own screen on that computer. Cursor's Grok Bot Terms say Bots of the same user must not be treated as separate security boundaries. Each user's work runs in a dedicated Firecracker microVM with hardware-level separation from other users, but nothing comparable separates your own Bots from each other.

**Can teams and enterprises use Grok Bot?**

Yes. Grok Bot is included with self-serve Cursor Teams Standard and Premium seats, where it is enabled for every member with no switch to turn it off, and SpaceXAI launched an Enterprise version on September 3, 2026. Cursor's docs list Enterprise-only controls including network policy, audit logs, Action Recording, SCIM, an MCP allowlist, and a switch to enforce Auto Review. Sign-in uses existing Cursor SSO and the computers run in the United States, while dedicated data loss prevention hooks, dedicated egress IPs, and on-premises deployment are not available. Enterprise pricing is not published.

**How does Grok Bot compare to OpenClaw?**

Grok Bot is the hosted, low-setup alternative to OpenClaw, the open-source, local-first AI agent you run yourself, and reviewers mostly frame the choice as ease against control. Constellation Research likened Grok Bot to a user-friendly OpenClaw, and early tester Lenny Rachitsky said it is like OpenClaw but easy, reliable, and less scary to use. The trade-off: Grok Bot runs only on Cursor-hosted computers, with no model choice and no deep configuration. That is why reviewer Claire Vo points people who want a tunable, transparent setup to OpenClaw or Hermes Agent instead.

## Sources
- [SpaceXAI — Introducing Grok Bot](https://x.ai/news/introducing-grok-bot)
- [Cursor Docs — Models & Pricing](https://cursor.com/docs/models-and-pricing)
- [SpaceXAI Docs — Grok Bot security](https://docs.x.ai/grok-bot/security)
- [Cursor Help — Grok Bot plans and billing](https://cursor.com/help/grok-bot/plans)
- [Cursor — Grok Bot Terms](https://cursor.com/terms/grok-bot)

---
Canonical page: https://www.sentientarc.com/blog/what-is-grok-bot
