← Back to research
·11 min read·company

Grok Bot

Grok Bot gives persistent personal agents a shared cloud computer, memory, skills, and routines, with access through Cursor and eligible Grok subscriptions.

Key takeaways

  • Grok Bot belongs in personal-agent platforms: persistent roles can use tools, produce files, and run recurring work while a laptop is closed.
  • Every Bot on one account shares the same cloud computer, files, and browser sign-ins; separate roles do not isolate credentials.
  • Paid Cursor plans include access, but weekly usage and optional on-demand charges determine the actual operating budget.
  • Shared Bot templates create copies; teams needing a shared review queue should also evaluate workflow platforms such as Tembo Agent Studio.

FAQ

What is Grok Bot?

Grok Bot is a hosted personal-agent product from SpaceXAI that runs named, persistent Bots on a cloud computer with browser, terminal, files, and connected tools.

How much does Grok Bot cost?

Access is included in paid individual Cursor plans, starting at $20/month, and Cursor Teams; eligible individual Grok or X subscriptions can also grant usage. Included weekly usage is limited, and optional on-demand work costs extra.

Does every Grok Bot get a separate computer?

No. All Bots belonging to one user share a computer, files, and browser sessions. Separate Bot screens and conversations do not establish separate security boundaries.

Can Grok Bot work while the laptop is closed?

Cloud tasks and routines can continue while the client is closed. Work that needs a human login, approval, or access to the local computer has additional dependencies.

Executive Summary

Grok Bot is SpaceXAI's personal-agent product for continuing work across applications. Named Bots retain context and use a hosted browser, terminal, filesystem, and connectors. Desktop clients cover macOS, Windows, and Linux; mobile clients cover iOS and Android. Cloud work can continue after the client closes.[1]

It belongs in Personal Agents Platforms: a user can assign goals, authorize actions, and return to persistent work. The strongest reason to evaluate it is a recurring job spanning several applications. The central tradeoff is shared access: all Bots on one account use the same computer and signed-in sessions.[2] This report reviews documentation and public experience as of September 16, 2026; it is not a hands-on reliability benchmark.

AttributeCurrent finding
Product and operatorSpaceXAI product; hosted execution uses Cursor infrastructure[1][3]
Organizing unitA person with persistent Bots; sharing a Bot gives the recipient a copy[4]
Entry subscriptionCursor Pro lists $20/month before taxes and includes Grok Bot access[5]
Technical boundaryDedicated Firecracker microVM per user, shared by that user's Bots[3]
Best initial evaluationOne recurring workflow with source evidence, a reviewable artifact, and a measured cost

Product Overview

Create a Bot around a durable responsibility, such as preparing a weekly account review. Its description establishes the role and lasting instructions; individual messages supply the current task. Saved preferences and summaries provide continuity, but changing facts should still be checked against current source systems. Duplicating a Bot carries its configuration and routines, not its conversation or learned memory.[4]

The conversation is also the work record. It shows tool activity, generated files, questions, and approvals. A user can redirect ongoing work with another message. Groups contain two to six Bots, and Bots can send asynchronous handoffs to each other. These features coordinate an individual's specialists; they do not establish a shared computer for multiple human coworkers.[6][4]

Key capabilities

CapabilityPractical useQualification
Persistent rolesReuse a specialist's working contextMemory needs correction and current-source checks[4]
Connected apps and computer useWork through a connector or a websiteInstalled connectors and browser sessions are account-wide[2]
SkillsSave an accepted procedureDemonstration-based teaching is still gradually enabled[7]
RoutinesRun scheduled or supported event-triggered workA test run performs real actions; it is not a simulation[7]
Reviewable artifactsReturn documents, spreadsheets, slides, or evidence foldersFile support does not guarantee correct contents or formatting[8]

A representative workflow

An appropriate pilot is a weekly account brief. Supply an approved customer list and a reporting template, connect the necessary sources, and request a dated document with links behind each claim. Require a separate section for missing information and leave customer communication awaiting approval. This is an evaluation design, not a workflow tested for this report.

The file interface supports common office documents, PDFs, structured data, media, and code. The desktop composer accepts six attachments at once, with 25 MB limits for documents, images, and audio, and 200 MB for video. Generated results appear in conversation cards for preview, saving, and revision.[8]

Once the output meets its acceptance criteria, save the method as a skill and attach a schedule with an explicit time zone. Current documentation limits each Bot to 50 routines and retains the 20 most recent run records per routine. Event triggers use Cursor account integrations, which are distinct from installing the corresponding app plugin.[7] Review several runs before judging whether the saved procedure reduced work rather than merely moving it into review.


Technical Architecture

One computer per person

Cursor operates the persistent computer, while the desktop and mobile applications provide the interface. Its documented isolation boundary is a Firecracker microVM per user. Grok Bot can delegate coding tasks to Cursor Cloud Agents on separate computers, subject to the organization's delegation controls.[3]

Within the personal computer, Bots share files, browser cookies, and command-line credentials. Each Bot has a screen and can perform one computer-use task on that screen at a time; separate screens do not isolate accounts. Durable project files belong in /workspace.[2] A sensible deployment therefore groups work by acceptable shared access, not just by convenient role names.

Approval and local access

Auto Review evaluates proposed actions with a model. Ask-first rules take priority over automatic-allow rules; a natural-language permission rule is not a proof that every harmful action will be caught. Personal rules are stored on the current desktop and synchronized to its cloud computer, so another desktop installation requires verification.[9]

Local command execution is a separate capability with ask-every-time, always-allow, and never-allow settings. The member default asks for approval; a stricter team policy wins. Cloud hosting should therefore not be described as a guarantee that Grok Bot cannot reach the user's device.[9]

Team controls and data

Self-serve Teams access is enabled by default, subject to legacy-plan and Legacy Privacy Mode exceptions. Enterprise administrators can enable access and restrict it by group. Network Controls, enforced team Auto Review, and organization computer management are Enterprise features, not benefits of every Teams seat.[3]

The security documentation identifies further boundaries worth checking:[10]

  • Network access: Without a policy, destinations are allowed. Blocking a connector does not also block the same service in the browser.
  • Credentials: Connector OAuth tokens remain on Cursor's backend; signed-in browser sessions still grant actions on the computer.
  • Models: Cursor selects the serving models. A customer should not assume the product name guarantees a fixed model or enforced provider list.
  • Privacy and retention: Privacy Mode's no-training setting is separate from persistent computer storage. Customer-managed point-in-time restore is unavailable.
  • Location: Computers run in the United States, but Cursor's separate US-only residency program does not automatically apply.

These are vendor-described controls, not an independent security certification of a particular deployment.


Continuity, Sharing, and Recovery

For an unreachable computer, the troubleshooting guide recommends retrying, restarting the client, and using recovery or image update before resetting. Recovery and update preserve durable files and logins; reset can lose unsynchronized work. An apparent stall may instead be an approval, expired login, usage limit, or website verification request.[11]

Routines also depend on an existing owner, valid source connection, correct time zone, reachable data, and available usage. Inspect the run history before rerunning a job that may already have changed an external system. The documentation's test action can perform real work.[11]

Public Bot sharing exposes its configuration and gives recipients a copy, without the original conversation or logins. Deleting a Bot removes its active conversation and routines but can leave shared computer files and sessions behind. Hiding it does not pause its routines.[4] Treat template distribution, stopping automation, and revoking access as separate operations.


Strengths and Cautions

  • Continuing context: Stable roles reduce repeated setup for recurring jobs; current-source verification remains necessary.[1]
  • Visible coordination: Bot-to-Bot messages and groups make specialist handoffs inspectable, although extra roles can produce redundant work.[6]
  • Useful coding handoff: A general assistant can collect context before a coding agent implements a change. SpaceXAI DevRel's September 11 guide demonstrates this division of responsibility.[12]
  • Review remains part of the workflow: Ask for source links, an editable artifact, and a record of unresolved assumptions. Producing a file is not evidence that its conclusions are correct.[8]
  • Operational dependence: A provider-hosted environment still encounters authentication, connectivity, and recovery problems. Evaluate those paths alongside the successful demo.[11]

What Developers Say

In an r/cursor discussion reviewed September 16, dizzygoldfish reported useful personal-data assistance but poor marketing and help-document writing, including an unwanted PR during revision. In the same thread, People_Change_ described setting up property-search and email assistants, while sprout-header reported useful browser-driven research but declined to trust it with customer communication. These are self-reported experiences, not verified performance measurements; the retrieved page's relative timestamps did not establish a dependable absolute publication date.[13]

SpaceXAI's Matt Palmer separately describes a Bot that collects development context and delegates implementation to Cursor Cloud Agents. His September 11 walkthrough is useful evidence of the intended workflow, with an explicit vendor affiliation; it is not independent validation.[12]

The practical inference is to test the exact deliverable. Successful retrieval or browser navigation does not establish that the same setup writes acceptable customer-facing copy, respects every approval boundary, or produces maintainable code.


Pricing and Access

Published individual Cursor prices checked September 16, 2026 are monthly US-dollar prices before tax; annual billing is advertised separately.[5]

Access routePublished cost or entitlementWhat to budget
Cursor Pro$20/monthIncluded Grok Bot usage[5]
Cursor Pro+$60/monthHigher Grok Bot limits[5]
Cursor Ultra$200/monthHighest individual Cursor Grok Bot limits[5]
Cursor Teams / EnterpriseSeat or contract termsTeams access included; Enterprise access administered[14]
Eligible linked subscriptionIndividual SuperGrok, Plus, Heavy, or X Premium+Grants usage to a Cursor account; does not stack with a Cursor grant[14]

There is no separate Grok Bot subscription. Included usage resets weekly; optional on-demand usage is billed through Cursor. The spending limit is not an immediate mid-run stop: an active job can finish past it. The free trial is a usage credit with a seven-day window, not seven days of unlimited work.[14]

The reviewed plan matrix does not publish a reliable tasks-per-week figure. Measure accepted output per dollar, including retries, reviews, and any separate connected-service subscriptions. Existing subscribers should test the included allowance before assuming they need the highest tier.


Competitive Positioning

The broader personal-agent comparison groups alternatives by execution location and operating responsibility. These are useful evaluation paths rather than a measured ranking:

AlternativeWhy evaluate it
LettaPersistent agents with git-tracked context, model/subscription choices, channels, and connected local or remote environments[15]
OpenClawOwn the gateway, state, and model configuration; accept deployment and security responsibilities, including optional sandbox setup[16]
TemboOrganize cloud coding-agent work around repositories, tickets, team visibility, and reviewed changes[17]
Tembo Agent StudioStage operational work in a shared Tasks Inbox with human review and actions through the reviewer's connected account[18]

Tembo is relevant when the recurring job becomes engineering work owned by a team: its current platform connects cloud coding agents to repositories, tickets, and tools, with scheduled or event-driven workflows and a self-hosted option. Disclosure: Ry Walker is Tembo's co-founder and CEO. The useful comparison is who operates the work and reviews its results, not whether every product can answer a chat message.[17]

Agent Studio makes the adjacent operational case more concrete. An agent can prepare a reply in a shared queue; the reviewer edits it and chooses an action that executes with their own connection's permissions. It also deduplicates items by source reference. That review model deserves evaluation when personal assistant output must become shared team work. The affiliation disclosure applies to both Tembo products; this is a comparison, not a claim of a Grok Bot integration.[18]


Fit and Outlook

Grok Bot is a reasonable pilot for a person who wants managed, persistent application work and is willing to review outcomes. Start with one repeatable deliverable, a small account set, and an explicit stop before external changes. Evaluate whether saved context improves the second and third runs rather than only the initial demonstration.

Prefer other deployment models when separate roles must never share credentials, provider choice must be enforced, or the primary need is a shared team review system. The architecture and security documentation make those distinctions material to procurement.[2][10]

Current product documentation and existing subscription access establish availability, not independently measured adoption, financial durability, or reliable unattended execution. The supported editorial outlook is that Grok Bot deserves a place in personal-agent shortlists. A recommendation for broad deployment should follow a representative pilot with recovery and approval failures included.


Research by Ry Walker Research • methodology