Clean up the Grok Bot shared computer
The cloud computer belongs to your account, not to a Bot. Cookies, saved logins and files are visible to all Bots and survive Bot deletion. Here's the inventory and cleanup procedure.
What the docs say
The computer belongs to your account, not to an individual Bot. Every Bot can see the browser cookies, saved logins and files on it; each Bot gets its own screen, not its own machine. Deleting a Bot does not guarantee the shared files or login state are removed.
Why it matters
The onboarding video shows a Bot taking over your logged-in browser. It's a great demo and the wrong default. Once your Gmail session is on that machine, the sales Bot, the recruiting Bot, and the Bot you made on a whim to find a sauna can all read your email. And so can anything that prompt-injects any one of them.
Inventory (30 minutes)
- Open the shared computer's browser as any Bot. List every signed-in site. Screenshot the list.
- List the files in the shared directory. Anything with credentials, exports of customer data, or your personal documents gets noted.
- List every connector under Settings → Plugins. Connectors are account-wide: authorising Gmail for one Bot authorises it for all.
Cleanup
- Sign out of every session that belongs to a human. Yours, your cofounder's, the intern's.
- Replace each with a Bot-owned account: see give a Bot its own account.
- Re-authorise connectors as the Bot user, with reduced scopes.
- Delete stray files. Move anything the Bots need into a clearly named folder with a README the Bots can read.
- Add a monthly routine: list signed-in sites and files, compare with the approved list, report differences. It's the Bot auditing its own house.
The rule going forward
Nothing human logs into the shared computer. Ever. If a routine truly needs your identity, that step is done by you, on your machine.
Give a Bot its own account · Prompt-injection exposure · Security checklist
Verified 28 Aug 2026 · Facts about Grok Bot change during beta. See changelog.