Which Grok bot this is
Three things get called a Grok bot, and only one of them does work while you sleep:
- Grok Bot, the agent. Launched in beta on 11 August 2026. Each bot has a name, a title and a description, and runs on a persistent cloud computer with a browser, files and a terminal, and it is the one this guide is about.
- The @grok reply bot on X. A chat feature inside the app. Nothing here applies to it.
- A bot you build yourself on the xAI API. The developer route. You pay per message with no free tier, and it needs code or a tool such as Zapier to run. This guide skips it.
Pay for a Grok Bot when the job lives inside an app it has to click around in, or has to run while you are away. When the job is "read these and tell me", the free Automation further down does it, and the cloud computer is the only reason to pay.
What it costs and what you need
- A paid plan. Grok Bot comes with every paid Cursor plan and Cursor Teams, and with SuperGrok, SuperGrok Plus, SuperGrok Heavy and X Premium+, per the plans page. Allowances differ by tier, so check what your own account shows before you pay.
- The prices, US pricing. On the Apple App Store listing in September 2026, SuperGrok is $30, Plus is $100 and Heavy is $300. Cursor Pro is $20 a month and lists Grok Bot access.
- The desktop app. Download from x.ai/bot for Mac, Windows or Linux. The phone app can create bots and approve requests, and desktop is required to edit routines or teach a task by showing it.
- A Cursor sign-in. Grok Bot signs in with a Cursor account, and Legacy Privacy Mode has to be off because the bot needs cloud storage.
If that price is too much, skip to the free version further down: a scheduled Automation on grok.com does the "every morning, check these and tell me" job without a cloud computer.
The setup, step by step
Every step below is on xAI's own setup page and its routines page, checked on 16 September 2026.
- Install and sign in. Open the desktop app, press Get started, then Sign In with Cursor.
- Create a new agent. Press Create new agent rather than picking a ready-made teammate, and fill in its profile: Name, Title, Description and an avatar. The Description is where the behaviour lives, so paste the first file below into it and fill in the brackets.
- Give it one small task. Use the second file below. xAI's own starter is a document summary in five bullets with "Do not change the source file", which is the right size for a first run.
- Hand over logins yourself. When a site asks for a password, a code or a CAPTCHA, open the Agent Computer, take over, sign in, and hand control back. Connectors install from Plugins in the sidebar, or from the Connect card that appears in chat when a task needs one.
- Review before anything leaves. The task file ends with a review point. Read what it made, then say "Save the process we just used as a skill" if you want it again.
- Answer the first approval properly. Your first Allow once or Deny prompt arrives during that task. Auto Review rules exist, and an Ask first rule beats an Allow automatically rule, so write the Ask first ones.
- Set a routine after a second clean run. Routines live under View conversation details, then Routines, with a success and failure history. They run on a schedule such as every weekday at 8:00, up to 50 per bot. Teach a task records ten minutes of you doing it, and a Test run does real work, so test on something harmless.
When it stalls
- It sits at a login screen. Open the Agent Computer, take over, sign in, hand back. Some sites block the cloud computer's address, so start with one you know works.
- It has been "working" for twenty minutes. Stop it. A vague task loops, and a loop spends your allowance. Run it again with the sources named.
- Your Cursor allowance moved. Usage is linked to the plan you signed in with, so if that is Cursor, expect its allowance to drop as the bot works.
1. The bot description
Paste this into the Description field. It makes the bot ask before it acts, stop at logins, refuse to invent, and report what it could not do.
You are [bot name], my [job title] and the teammate I trust with real work on a computer I cannot watch all day. Your job is to finish [the one job, in one line] and hand me something I can act on. Being fast matters less than being right, because I will not always be there to catch a mistake before it lands. WHAT I HAVE GIVEN YOU - The one job: [describe it in one line, with the outcome that counts as done] - Where the work lives: [the apps, sites, folders or documents you may use, by name] - What good looks like: [a finished example, or the shape of the deliverable] - Who you report to: me, in this chat, and nobody else BEFORE YOU START ANY TASK Check that you have all five of these. If any is missing, ask me for it in one short message and wait. 1. The outcome: what should be true when you are done. 2. The sources: which files, sites or accounts to use, and which to stay out of. 3. The constraints: anything you must not change, send, buy, post or delete. 4. The deliverable: the shape you hand back (a document, a table, a draft, a list of changes). 5. The review point: what you show me before anything leaves this computer. HOW YOU WORK - Say what you are about to do in two lines before you do it, so I can stop you. - Work in the actual tool, and keep a running note of every change you make and where it is. - If a site asks for a password, a code or a puzzle, stop and hand control to me. Never guess a login and never store one in a note or a message. - If something looks different from what I described (a page has changed, a file is missing, a number does not add up), stop and tell me rather than improvising. - If a task is taking far longer than it should, stop and report where you are. A loop costs me money. NEVER, WITHOUT MY EXPLICIT APPROVAL IN THIS CHAT - Send, post, publish or reply to anyone. - Pay for anything, change a plan, or accept terms. - Delete, move or overwrite a file, a setting or a record. - Change anything in a live or production system. - Sign up for a new service or create a new account. NEVER INVENT - Never invent a number, a name, a date, a quote or a source. If you could not find it, write "[NOT FOUND: what]" and move on. - Never claim you did something you did not do. "I updated the sheet" must mean you can point at the row. - Never say a task is done when part of it is blocked. Say which part. FINISH EVERY TASK WITH - What you did, as a short list, with where each change lives. - What you could not do, and why. - Anything you were unsure about, named plainly. - The one thing you need from me next, if anything.
2. The first task
Every task gets the same five parts, which is the shape xAI's own examples use. Start with something that cannot go wrong, such as summarising a document you attach.
Task: [name it in five words] OUTCOME [What should be true when you are done. One sentence.] SOURCES Use: [the file, site or account, by name] Do not touch: [anything off limits] CONSTRAINTS - Do not change the source file. - Do not send, post or buy anything. - If you need a login, stop and hand control to me. DELIVERABLE [The shape: five bullets, a table, a draft in a new document] REVIEW POINT Show me the finished deliverable here in chat before you save, send or file anything. Then stop. Start by telling me your plan in three lines, and wait for my go-ahead.
Filled in, a good first task and a bad one look like this.
Good. Task: summarise the attached PDF. Outcome: five bullets I can read in a minute. Sources: the attached file only. Constraints: do not change the file. Deliverable: five bullets. Review point: show me here, then stop.
The bot replies with a three-line plan and waits, which is the whole point.
Bad. "Find out what my three competitors charge and put it in a sheet."
No named sites, a login wall somewhere, and a spreadsheet it may write to. Three of the five parts are missing, so it either stalls at a login or fills the gaps itself.
3. The free version: an Automation
Automations are scheduled prompts at grok.com/automations and in the Grok app, and scheduled ones are available to everyone. Email triggers need SuperGrok. The fields are Name, Instructions, Connectors, Skills, Triggers, Mode and Notification, and Run now tests it. Only the numbered instructions go in the Instructions box; Name, the schedule and Notify are set in the form.
Name: [Monday brief] Instructions: Every [weekday] morning, do this and nothing else. 1. The job: [for example, read the three sources below and tell me the five things that changed since last time]. 2. Sources: [the sites, feeds or connectors you may use, by name]. Use nothing else. 3. Format: [five bullets, each under 25 words, with a link for anything factual]. 4. If a source is down or has nothing new, say so in one line rather than padding. 5. Never invent a figure, a quote or a link. If you could not confirm it, leave it out and tell me. 6. End with one line: what you were unsure about, or "nothing unclear". Schedule: [weekdays, 8:00, your time zone] Notify: [email, app, or both]
Keep a copy of the bot outside the app
Once a bot works, save its definition somewhere you control. Dr Josh Simmons published GBDL on 8 September 2026, MIT licensed: one Markdown file that records a bot's persona, connectors, onboarding and routines so you can rebuild it. He says plainly it is his format and no official one, and his one rule is no secrets in the file.
xAI's own route is templates: Share as Template, and someone presses Add to Grok Bot. Templates do not include secrets either.
The honest bit
- One computer, every bot. xAI's security page says "Do not use separate Bots as a security boundary". All your bots share one computer, its sessions and its credentials, so every login you hand over lives there.
- Usage can run away. Allowances reset weekly and on-demand usage sits on top. Flavio Copes, in a write-up updated 30 August 2026, found vague instructions send a bot into usage-draining loops, and some sign-in sites block the cloud computer's address.
- The plan list has already moved. The tiers that qualify changed within weeks of launch, and two official pages still disagree on the lower ones. Check your own account before paying.
- The trust question is live. On the launch thread on Hacker News a recurring objection was handing a bot your credentials, and the bot browses the web with them.
- A chat-side leak is on the record. Adversa AI showed on 20 August 2026 a zero-click leak of chat data from Grok's web chat through a booby-trapped page, reported to xAI in June and unpatched at publication. That was the chat product, so keep Ask first rules wide and Allow automatically rules narrow.
Do the five-bullet summary first
Install the app, create one bot with the description above, and give it a document to summarise using the task file. Watch it in the Agent Computer once, read the review point, and only then decide whether it earns a routine. If the price is the problem, set up the Automation instead and you still get the morning brief.
If what you want is several bots with one in charge, building an AI team with one boss is the same shape without the cloud computer.
A few quick questions
Do I need the desktop app?
Only for editing routines and teaching a task by showing it. The phone app can create a bot and approve its requests, and the work carries on in the cloud after you close the app.
Can it get past a two-factor code or a CAPTCHA?
No. It stops, hands control to you inside the Agent Computer, and carries on once you are through. That is by design, so never paste a code into the chat.
Is there a Grok bot for Telegram?
Yes, xAI's official @GrokAI bot on Telegram, free to Telegram Premium subscribers. Its listing still says Grok 3, and it is a chat bot with no cloud computer, so it cannot do the work above.