Grok Bot, Two Weeks In: The Always-On Agent Workforce Gets a Shared Computer and a Shared Security Boundary

Written by

in

by Chris DePuy / August 29, 2026

xAI launched Grok Bot in early beta on August 11, and in the two weeks since, the community has made the platform’s ambition concrete faster than the company’s own launch materials do. The product is not another chat interface — a Bot gets its own cloud computer, signs into the tools and websites a human worker would use, works 24/7, and comes back only when something needs approval. What started as xAI’s internal prototype for sales outbound, office ops, and bug-fix work is now being operated as a genuine small workforce by individual subscribers, and that shift raises both an economic question and a security one that the launch page does not answer.

A Computer of Its Own, Sold Through the Subscription Stack

The core design decision is that Bots work inside the actual apps — inboxes, CRMs, and websites reached through a shared computer in the cloud, including platforms with no clean API or MCP. A user messages a Bot like a colleague, can teach it a routine by letting it watch a job done once, and multiple Bots coordinate in group chats under a chief-of-staff arrangement. xAI says the work lands “in the actual tool,” and its sales team’s outbound Bot researches accounts overnight and leaves a queue of drafted emails and LinkedIn messages for approval, while an ops Bot processes invoices arriving in Gmail and an engineering Bot reproduces a bug in the product UI before handing the fix to a debugging Bot.

Modern office workspace representing the Grok Bot always-on agent workforce
Grok Bot gives each subscriber an always-on agent workforce with its own shared cloud computer. Source: Unsplash stock photography.

The commercial structure is what makes this more than a demo. Grok Bot has no standalone price; it rides on premium tiers that were already in market — Cursor Ultra at $200 per month, Cursor Premium Teams at $120 per seat per month, and included in xAI’s own SuperGrok Heavy tier, with enterprise routed to a waitlist. Each of the jobs xAI describes occupies an entry-level or operations hire today, and the product is priced, at roughly $120 to $200 per month, well below a loaded salary for that work. Bundling an agent workforce into subscriptions customers already pay for is a cheaper distribution path than selling agent seats from scratch, and it visibly ties xAI’s agent strategy to Cursor’s — the download, onboarding, and sales contacts all run through Cursor infrastructure.

The Community Is Already Running It as a Company

Two weeks has been enough for the operating patterns to emerge. The most coherent one is what one practitioner calls the agent passport: give a Bot an inbox and calendar, access to a company bank account, a spend card with hard limits, a crypto wallet, a signing key, a phone number, a domain, and an X account — the stack a standalone legal entity would carry, wired to a single always-on agent. Others describe running a chief-of-staff Bot that manages the other agents, and a collection of more than 170 plug-and-play Bot configurations for marketing, sales, and operations has circulated as open-source prompts. None of this is officially endorsed by xAI, but it signals where the user base is taking the platform: not toward a smarter assistant, but toward delegating standing roles with real financial and account access.

The Shared Security Boundary Is the Constraint

The reason the agent-passport pattern is notable, rather than merely clever, is that xAI designed the security boundary around a shared computer. Every Bot on an account shares one cloud computer, its files, browser sessions, and logins; an independent analysis counted eleven signed-in apps reached by several Bots running under one account, with everything left standing after a Bot was deleted. The official documentation states plainly to “Do not use separate Bots as a security boundary,” and warns that any login placed on the shared computer is available to every Bot. That is the opposite of the operating posture the cyber agencies of the US, UK, Canada, Australia, and New Zealand published in May for agentic access, which called for no broad or unrestricted access and low-risk, non-sensitive tasks only. The tension is structural: the very thing that makes a Bot finish a job end to end — unrestricted access to the tools where the work lives — is the thing that maximizes the blast radius of a single compromised or prompt-injected session. xAI has already acknowledged the friction in its first two weeks, and multi-account support is reported to be on the roadmap.

For an enterprise, the economics of an always-on workforce are attractive enough to justify the deployment, but the identity model is not yet enterprise-grade. To the extent this tier matures into real digital labor, the defining engineering problem will be how to give an agent authority over the tools it needs without giving it a single shared key to everything. As firms such as 650 Group have been tracking in their AI infrastructure research, the desk-side and small-team agent tier is becoming less a model question and more a question of identity, authorization, and the boundaries around the compute the agents share.

More posts

© MarketIntelligenceResearch.com