Grok Bot security checklist

The checklist we run on every Grok Bot account: identities, shared computer, connectors, approvals, injection exposure, spend, offboarding. Printable.

Short answerTwelve checks. If more than three fail, book the audit before the next unattended run.
  • [ ] No human account is signed in anywhere on the shared computer
  • [ ] Every Bot has its own email and its own seat/user in each tool
  • [ ] Every token was created from a Bot account and scoped to its routines
  • [ ] No token has ever been pasted into a chat message
  • [ ] Every connector under Plugins is authorised as a Bot user
  • [ ] Composio (if used) authorisations reviewed and attributed
  • [ ] Every routine that reads outside text has no unattended send/pay/delete/settings powers
  • [ ] Approval rules written per routine: never / always / threshold
  • [ ] Bot-to-Bot instructions to act are treated as requests for approval
  • [ ] On-demand rule set; spend watcher at 60/85%; kill procedure practised
  • [ ] Heartbeat log in place; silent failures surface within a day
  • [ ] Offboarding order documented for each Bot (revoke → remove connector → sign out → delete files → delete Bot → delete email)

Each item links to its fix in the fixes directory. We review these controls before Manage My Team begins.

Verified 28 Aug 2026 · Facts about Grok Bot change during beta. See changelog.

Build Grok Bot Team