Grok Bot: current capabilities and limits
Grok Bot is xAI’s persistent agent, shipped as an early beta on 11 August 2026: a cloud computer, sign-in to existing tools, work that continues while nobody is watching. Auth is a Cursor account. Every bot on the account shares one cloud computer. They look like a team. Isolation is the account, not the bot.
Not the Agent in the editor
Agent mode in the Cursor editor edits the repo and runs tests. Close the window and it usually stops. Grok Bot work does not live in that window. It runs on a persistent cloud VM with a browser, a filesystem, and a terminal. Connectors and MCP where they exist; computer use where there is no clean API. The same Bot is on desktop and iOS. Quit the app, close the laptop, lock the iPhone: the current turn and any routine keep going.
The machine is shared
Several bots look like colleagues. They are extra screens on one machine. Shared: cookies, signed-in sessions, files, CLI credentials. Work one bot writes down, another can continue. Durable files go in /workspace.
Each bot can drive a browser in parallel. One bot, one computer-use task on its own screen. Screens separate clicks, not secrets. Do not treat separate bots as a security boundary. A secret on that computer is available to every bot on the account.
The cloud computer is not the Mac or Windows box on the desk. Local commands: Settings → General → Agent → Execution on Local Computer, default Ask every time. Never allowed only with a reason. That setting does not touch the cloud computer. iOS cannot change it.
Passwords, passkeys, 2FA, CAPTCHAs, and payments are takeover steps. Do not paste them into chat. A supported connector can raise a masked secret request; the value stays out of the transcript. Settings → Beta: Update keeps durable state, Reset drops unsynced work. Prefer a Plugin. Connectors are account-wide: install once, every bot can reach them.
Caps and handoff
An account can have 50 bots and group chats combined. Create with Cmd/Ctrl+N. Standing rules in the description, the current task in the thread.
The labels understate the action. Hide does not pause the bot or its routines. Delete removes the profile, the conversation, and the routines it owns. Files and logins on the shared computer stay. A share link is a public photocopy of the configuration: identity, description, skills, routines. Not the computer. Not the logins.
A group is two to six bots. @ to name one. Handoff can be asynchronous. Between bots in a group, text only; send an image to the bot that must see it. A new message preempts background work. “Stop now” stops immediately and does not undo completed actions.
Skills and routines
A skill is how. A routine is which bot, and when. Skills work across bots if the login is still there. / for a skill, @ for a bot, group, routine, or connector.
Teach a task records a browser workflow in a one-to-one computer view, up to ten minutes, no microphone. The result is a draft, not a finished skill. Cap: 50 routines per bot, 20 recent runs each. Deleting a routine has no undo. A test run changes files and calls tools.
Slack and GitHub events use Cursor account integrations, not the same auth path as those plugins. Do not trigger on every new message. After a long absence, routines may pause. Sidebar Sections need v1.2.0+.
Metering
Who gets Grok Bot is on the Cursor billing page: paid individual Cursor (Pro, Pro+, Ultra) and every self-serve Teams seat. Teams does not need a Premium seat. The FAQ lists fewer plans. Individual SuperGrok, Plus, Heavy, or X Premium+ can link as a usage grant without changing the Cursor plan. SuperGrok Team and Enterprise cannot link. Lite is not included. Cursor Enterprise goes through the account team.
The launch post said usage was separate from Grok and Cursor plans. Current metering is on the Cursor account, weekly, then on-demand if enabled. A SuperGrok or X link cannot be unlinked. The trial is a credit plus a 7-day window, drawn by agent steps and tokens. One large run can exhaust it. Used credit is not restored. macOS and iOS share one bucket and one cloud computer. No public weekly token count or official dollar price.
Approvals
Sending, publishing, buying, deleting, changing permissions, changing production, accepting legal terms: state the stop in the request. An approval covers the next action, not work already done. Desktop: Allow once / Deny / Always allow. In Auto Review, Require Approval wins over Always Allow. Rules live on the current desktop and sync to its cloud computer.
Cloud storage is required. Legacy Privacy Mode is not supported. Training opt-out follows the Cursor account. Withdrawing access is several steps: pause routines, sign out, uninstall connectors and revoke them at the source, clear /workspace. Deleting a bot does not clear shared sessions.
Platforms
- Supported: macOS (Apple silicon / Intel), Windows (x64 / Arm64), iPhone on iOS 18+
- Not at launch: Linux desktop, Android, iPad
- Still rolling out: Teach a task, cross-conversation search, iOS push