Grok Bot security checklist
The checklist we run on every Grok Bot account: identities, shared computer, connectors, approvals, injection exposure, spend, offboarding. Printable.
Short answerTwelve checks. If more than three fail, book the audit before the next unattended run.
- [ ] No human account is signed in anywhere on the shared computer
- [ ] Every Bot has its own email and its own seat/user in each tool
- [ ] Every token was created from a Bot account and scoped to its routines
- [ ] No token has ever been pasted into a chat message
- [ ] Every connector under Plugins is authorised as a Bot user
- [ ] Composio (if used) authorisations reviewed and attributed
- [ ] Every routine that reads outside text has no unattended send/pay/delete/settings powers
- [ ] Approval rules written per routine: never / always / threshold
- [ ] Bot-to-Bot instructions to act are treated as requests for approval
- [ ] On-demand rule set; spend watcher at 60/85%; kill procedure practised
- [ ] Heartbeat log in place; silent failures surface within a day
- [ ] Offboarding order documented for each Bot (revoke → remove connector → sign out → delete files → delete Bot → delete email)
Each item links to its fix in the fixes directory. We review these controls before Manage My Team begins.
Verified 28 Aug 2026 · Facts about Grok Bot change during beta. See changelog.