TL;DR
Stop asking what a bot can do for you. Ask which roles you can stop doing yourself: research, writing, outbound, triage, analysis, quality control.
Every bot you create shares ONE cloud computer, so two bots are not two security walls, and access widened on 21 August, so the “$200 floor” posts are stale.
xAI’s own order is prove the workflow, build the skill, add specialists, automate. Most people start at specialists and blame the model.
You are the entire company
You find the leads, write the outreach, make the images, answer the replies, count the week. Nothing gets handed off because there is nobody to hand it to.
Most AI tools do not fix that. They make you faster inside every task, but you are still the one clicking.
The question that changes the week is not “what can this thing do for me?” It is: which roles can I stop doing manually?
Research is a role. Writing, outbound, inbox triage, analysis, quality control and coordination are roles. Once each has an owner, your bottleneck stops being how much you can finish. It becomes how much you can clearly hand off.
Grok Bot is the first tool where that is real for me, not a pitch, for a structural reason: the agent gets a computer, logins, memory and a clock. I have written about AI agent loops and folder-native agents. This is the operator’s version.
What Grok Bot actually is
xAI’s new product, in beta since 11 August. Not the Grok chatbot on X, not the API. A bot here is a worker, not a chat window. Each one has:
A name and a defined job
Its own memory of how you like things done
Real access to your tools, through plugins or its own browser
A computer in the cloud where it works
Skills: saved ways of doing a task, learned by watching you once
Routines: those skills running on a schedule, with nobody in the chat
Approval rules for anything that needs a human
A chat session dies when you close the tab. A bot with its own computer and a schedule does not.
Here are mine running Monday standup while I watch from outside the room. Sound on:
Mira holds the newsletter until she gets a yes. Holt takes the orphan tickets. Ivo will not move a calendar clash without approval. Nobody asked them to be careful in the moment. Their charters did.
The one fact that changes your whole design
Every user gets one computer in xAI’s cloud. All your bots share that same machine. Each gets its own screen, so several work in parallel, but underneath they share everything: files, browser logins, sessions, credentials.
Two consequences. Bots can collaborate, one writes a file, another reads it. And two bots are not two walls: a second bot can reach every login the first one left on the machine. Almost every guide this week implies the opposite.
Persistent is also not permanent. Keep durable output in the /workspace folder, and copy anything that matters to a place you own. Your files, your docs, your CRM.
Access, accurately
The beta opened 11 August for the top plans only. On 21 August xAI widened it. In now: SuperGrok Plus and Heavy, Cursor Pro+ and Ultra, Cursor Teams Standard and Premium. Plain Cursor Pro is out.
Everyone else gets a one-time trial: a credit that lives seven days, and spent credit does not come back. Do not open it with a vague task that could run for hours. One sprawling job can eat all of it.
Platforms: Mac and Windows desktop, iPhone on iOS 18+. No Linux desktop, no Android. All beta-dated, check your own plans page.
The ladder, in xAI's own order
An engineer at xAI published the sequence: prove the workflow, build the skill, add specialists, automate.
Read the failure mode in it. Almost everyone starts at step three, spins up eight bots on day one, gets mush, and blames the model. The model is fine. The order was wrong.
Rung 1: one bot, one narrow job. A prompt is a request, a bot is a role. A weak first bot is called General Assistant and its instruction is “help me with anything”. A good role answers six questions: what it owns, which sources, which tools, what good output looks like, what needs approval, what to do when information is missing.
ROLE
You are [name], [job title].
You own [the outcome, not the task list].
SOURCES YOU MAY USE
[the exact dashboards, inboxes, folders, sites]
If a source is unavailable, do not guess.
Say so and continue with the rest.
TOOLS YOU MAY USE
[only what this role needs. Nothing else.]
WHAT GOOD OUTPUT LOOKS LIKE
- Saved to /workspace/[folder]/YYYY-MM-DD.md
- Every claim linked to its source
- Facts separated from your interpretation
INSIDE THE FENCE
Read connected tools, gather evidence, prepare drafts.
OUTSIDE THE FENCE, ASK FIRST
- Send anything to a person outside my company
- Publish anything
- Spend money, or commit to a price or a date
- Delete anything
- Anything irreversible
WHEN UNSURE
Stop. One message with your proposed action and why.
Do not guess. Do not ship half and call it done.Nothing in there tells the model to be brilliant. Those words do not define work. The charter defines sources, evidence, output location, stopping conditions and authority.
Rung 2: connect tools in the right order. Plugin first, always: named actions, clean data, no hunting for a button that moved. Browser second: the bot drives a real browser on its computer, you sign in once, and at a password or payment screen it hands you the wheel. Your own laptop last, and only when the file exists nowhere else.
Never paste a password into the chat. Use the secure credential request, which masks the value. The bot holds a session, not a secret. And connect only what this week needs: connections are account-wide, so one connected inbox belongs to every bot you will ever create.
Rung 3: run it once, demand something you can check. Not “keep an eye on things”. A file you can open. Grade the run: right sources, nothing saved in the wrong place, facts separate from guesses, stopped before the risky action. Then correct the process, not the paragraph. Fixing the output teaches nothing. Fixing the procedure becomes a skill.
Rung 4: teach by showing, then give it a clock. Hit Teach a task, do the job once while it watches, stop. It saves a reusable skill. Pick the first task on three tests: weekly or more, two or more tools, steps rarely change. Then a schedule or a trigger, said in plain chat, with output landing in a folder you already open.
The Saturday test
Friday always looks good. You are in the chat, you unstick the handoff, you click send. Then you close the laptop, and Sunday either something happened or nothing did.
If nothing happened, you did not hand off a role. You built a chatbot with extra steps. If the job only moves while you are in the thread, the brief is wrong. Fix the brief. Do not add a manager bot to babysit the first bot.
A job stays draft-only until its routine is boring.
Then hire the rest
Specialists first, coordinator last. My six:
Carl, CEO. The only bot I message daily. Outcomes, not tasks. Asks before money, publishing, deletion.
Mira, CMO. Drafts from my past writing so the voice holds. Never publishes.
Nash, Head of Product. Owns the support queue and the pricing test. No winners on thin data.
Holt, CTO. Reproduces bugs, lands fixes on a branch. Never touches production.
Lina, COO. Vendors, invoices, follow-ups. Flags mismatches, changes nothing without a yes.
Ivo, Chief of Staff. Calendar and filings. Does not book without me.
Wire them by outcome, not by bot: one group chat per goal, and give the group the goal, not a task list. A task list means you already did the thinking you wanted to hand off.
The honest part
Bots are not walls. One shared computer, shared logins.
No self-hosting, no memory export. The computer is xAI’s, and you cannot inspect or delete what a bot remembers.
One model. No swapping in a different AI per task.
Two surfaces. Desktop and iPhone. No Slack, no email, no Android.
Browser work is fragile. A redesigned page can trip a routine. Expect to re-teach.
Early beta. Eleven days old. The promise is real, the proof is not in yet.
Who it suits: you already run several AI tools daily and the bottleneck is that you must be present. Who it does not: you are still learning what these models can do. Get fluent with one assistant first.
Your first hour
Pick one job you do weekly, touching two or more tools, steps rarely change.
Create one bot. A name a person could hold. Fill the charter, fence at the bottom.
Connect the one plugin it needs. Nothing else.
Run it once, watching. Correct the process, not the paragraph. Run again.
Two clean runs, then teach it by demonstration and set the schedule.
Leave.
What ran while you were not in the chat is the only number that counts.
Frequently asked questions
Do I need SuperGrok Heavy or Cursor Ultra?
Not since 21 August. Eligible: SuperGrok Plus and Heavy, Cursor Pro+ and Ultra, Cursor Teams Standard and Premium. Plain Cursor Pro is excluded, and there is a one-time seven-day trial credit.
Does each bot get its own computer?
No. One cloud computer per user, shared by all your bots. Each has its own screen, but files, logins and credentials are shared.
Is a second bot a way to isolate risk?
No. A credential on the shared computer is reachable by every bot you create later.
Where do credentials go?
Never into the chat. Use the secure credential request, or take over the browser and sign in yourself. The bot keeps a session, not a secret.
Why did my trial credit vanish so fast?
One vague, long-running first task. Spent credit does not come back. Start small, with a defined output file.
How do I know a role has actually been handed off?
Close the laptop on Friday and read the output folder on Sunday. That is the whole test.
Key takeaways
Ask which roles you can stop doing, not what a bot can do for you.
One shared cloud computer. Bots are not security walls. Design around that first.
Prove, then skill, then specialists, then automate. Starting at specialists is why setups fail.
Correct the process, not the paragraph. That is what becomes a skill.
Reversible work runs inside the fence. Irreversible work waits at it.
Further reading
xAI, Introducing Grok Bot - https://x.ai/news/introducing-grok-bot
xAI docs, Connectors - https://docs.x.ai/grok/connectors
Flavio Copes, A deep dive into Grok Bot - https://flaviocopes.com/grok-bot/
Vellum, Grok Bot Breakdown - https://www.vellum.ai/blog/official-grok-bot-breakdown
About the author
Eugeniu Ghelbur builds AI tooling and writes The AI Operator. He maintains obsidian-second-brain, an open-source LLM-first second brain used by over 4,200 developers. He writes about what holds up in production and what quietly breaks.







