Set Up Your First Grok Bot Routine, and Decide What to Keep Away From It
Set up a read-and-draft Grok Bot routine first, check its output against the source, and keep anything you cannot undo off the shared cloud computer.
Grok Bot is an app from SpaceXAI, the name now on the x.ai site. In it you create named AI agents called Bots. Every Bot you own shares one persistent cloud computer with a browser, files and a terminal. So a routine can run on a schedule while your laptop is closed.
A tester at DataCamp gave one such routine a weekly job: build a learning plan for a learner with a three-hour budget.
The routine left out every candidate course, because each was off-topic, had a prerequisite the learner lacked, or listed no length. It returned a total of zero rather than fill the week with courses that broke the tester's rules.
A routine does what its rules allow, so the rules need the care.
This guide walks through the setup steps from the docs and DataCamp's tutorial, then it sets a limit on what that routine, and every later one, should be allowed to touch.
What does Grok Bot run on, and what does it cost?
There is no separate Grok Bot subscription.
Access arrives through a plan you may already pay for. Some early reviews quote $200 a month. But Cursor's pricing page lists Cursor Pro at $20, and xAI's 2026-08-26 post lists Cursor Pro among the included plans.
Table: Ways to get Grok Bot access (as of 2026-10-05)
| Route | How you sign in | What you get |
|---|---|---|
| Cursor Pro, Pro+ or Ultra | The same Cursor account | Weekly Grok Bot usage, larger on higher plans |
| SuperGrok, Plus or Heavy | Link your Grok account | A usage grant on your Cursor account |
| Cursor Teams (Standard or Premium) | Your seat | Usage drawn from the seat's allowance |
Cursor's plan page says a Cursor plan and a linked SuperGrok subscription do not add their usage together.
The weekly allowance resets every week. When it runs out, extra use bills through Cursor as on-demand usage. That is usage beyond the weekly allowance, billed to your card. This guide calls it paid spillover. It needs the setting turned on.
To find it, open Settings in Grok Bot and look for "On-demand monthly limit". Choose Enable if it is off. If the app asks for a card, finish on the web at cursor.com/dashboard, under Spending, in "Monthly Limit".
A monthly limit is no hard stop mid-run. A Bot already working can finish past it. Treat the cap as approximate.
Still, Cursor staff told one user that a $0 on-demand limit prevents any paid spillover, so set that limit before the first routine if you want none.
Separately, coding work a Bot hands to Cursor cloud agents bills to regular Cursor usage.
Cursor does not publish the weekly allowance as a number, according to one reviewer. Watch usage for the first week.
How do you set up your first recurring task?
xAI's docs give the order: run a one-time task, make it reliable, save it as a skill, and only then automate it. A skill stores the steps. A routine sets the schedule.
Automate only after a hand-run version has been checked against its source.-
Install the desktop app and sign in with Cursor. Grok Bot needs cloud data storage, so an account in Legacy Privacy Mode (a Cursor privacy mode that does not store data, which Grok Bot cannot run in) must change its data setting first. Change it in Cursor privacy settings.
-
Create a Bot with one job. Your first Bot comes from the welcome flow. Choose Meet a future teammate or Create your own. Give it a short name, one primary job and a description. Add later Bots with New, then Create new Bot.
-
Keep the rules and the inputs apart. Put the rules that never change in the Bot's description. Keep weekly inputs, such as a goal or a budget, in a file in the shared workspace, /workspace, which the Bot can read. DataCamp used /workspace/learner-profile.md, because Bot memory is not a reliable record of changing details. Its tester saw a new Bot treat its profile as a live task and start an unrelated plan. Two rules fixed it. Ask when the goal is ambiguous. Never create accounts, enroll or purchase.
-
Run the job once by hand. The docs suggest naming five things so the Bot has nothing to guess. Name the outcome, the sources, the limits, the deliverable and where the Bot stops for you. Choose a job whose sources are public, so no login is needed. DataCamp's first task prompt follows. Swap in your own public-source job and keep the same five parts.
The full prompt, from DataCamp's tutorial:
Build me a weekly DataCamp learning plan. The learner is comfortable with Python, understands basic LLM concepts, is new to AI agent orchestration, and has 4 hours available this week. They prefer practical, hands-on material over theory. Search current DataCamp content on AI agents. Open each candidate's resource page before you consider it. Pick a small number of resources whose page-listed durations total 4 hours or less, and order them from foundations toward practical application. For each resource, return the title, the content type, the level and duration exactly as printed on the page, the link, one sentence on why it fits this learner, and its position in the order. Then give me the total time and one learning objective for the week. Do not use search snippets as evidence. If a page does not list a duration or a level, write "not listed" instead of estimating. If the goal is too broad to plan against, ask me before you continue. Stop after the plan. Do not enroll me in anything.Telling the Bot to write "not listed" instead of estimating keeps it from guessing. "Do not enroll me in anything" stops it before it acts.
-
Read the output against the source. Check links, levels, prerequisites and time. DataCamp's run shows why.
- The Bot labeled a course Beginner when its page said Basic.
- The tester's prompt had said to copy the level exactly as printed. Wording lowers the risk. This step catches the rest.
- Two duration fields disagreed: a 2 hr estimate in the summary and a 1 hr - 3 hr chip. The Bot copied the chip. It treated the upper end as a fixed total.
- The fix: name the field used and keep both printed values. Use the highest upper bound only for the budget check.
- Two more questions help. Is there a real progression, or interchangeable courses? Did anything get in only because a keyword matched?
-
Save the process as a skill. The tester asked the Bot to save a skill called "Weekly DataCamp Learning Plan", which reads /workspace/learner-profile.md and checks each prerequisite against the learner's background.
- It adds the page durations and returns the agreed fields. Then it stops before any action that needs approval.
- Keep yours narrow: use one source family, one output format, one approval boundary.
- A useful skill states when to use it, the inputs and access, the sequence, how to validate, what to return and what needs approval.
- Then run it once on a different input. DataCamp's tester found a missed prerequisite that way, and then told the skill to compare every prerequisite with the learner profile and to report every conflicting duration field.
- Type / in the composer to reference a saved skill.
-
Add Ask first rules before you schedule anything. Open Settings, then General, then Auto-review, and add rules there. There are two kinds. Ask first always stops a matching action for you, while Allow automatically lets a matching action proceed only if the automated review, called Auto Review, finds no other reason to stop. When both match, Ask first wins. The guidance gives two examples: "Ask first before sending any external email." and "Ask first before changing a production dashboard." Write yours in the same shape. Guard these first: sending, publishing, purchases and transfers, and deleting data.
-
Create the routine. Set the time zone first. DataCamp did it under Settings, General, Agent. Then ask the Bot that should own the job. Confirm the owning Bot, the schedule and time zone, the input source, the expected result, the approval boundary, and what to do if a source is missing. The Bot creates the routine and shows the next run. To find it later, open the Bot, choose View conversation details, then Routines. There you can enable or pause it, run a test, edit it and read the run history.
-
Run a test. A test run does real work: it can browse sites, change files and call connected tools. Use safe inputs and keep write actions behind approval. Then check that it used current inputs, matched the required format, stopped at the intended approval point and reported failures plainly.
-
Review the run history. Use the Routines page from step 8, where a run appears in Run history with a completion check and the result stays in the Bot's conversation. Check recent successes and failures against the source, as in step 5. If a routine never started, DataCamp advises checking that it is on, its details and the remaining usage, and usage lives under Settings, then Usage & Billing. The checklist below covers the same ground.
The docs' own example routine shows the shape of a routine prompt. It has a schedule, a skill to run, a place to post the result, a boundary and a rule for missing data:
Every weekday at 8:00 AM, run the Daily customer-risk skill against the current account list. Post a linked watch list in this conversation. Do not contact customers. If the source data is unavailable, report the failure instead of using old data.
That is a customer-data job. Its inputs, a customer list, are more access than a first routine needs. Copy its last two sentences. Leave its inputs. One sets a boundary. The other says what to do when a source goes missing.
For a map of the other ways to schedule AI work, Build to Launch has a complete map of AI scheduled tasks.
What happens when the routine runs without you?
After a long absence, Grok Bot may ask whether to keep routines running and pause them if you do not reply. Review anything paused when you return.
When a routine reaches an action that needs approval, the conversation shows the proposed action and its inputs. You choose Allow once, Always allow or Deny, and the iPhone app has the same controls. The overview says the Bot comes back when something needs your approval. The pages do not say what a routine does if nobody answers.
If a routine did not run, the troubleshooting page gives a checklist:
- It is enabled.
- The schedule and time zone are right.
- The owning Bot still exists.
- Required plugins remain authenticated.
- The computer can reach the source system.
- Usage or account access is not paused.
Three details catch people:
- One tutorial reports that hiding a Bot does not stop its routines. Pause the routine, or delete it. Deleting a Bot also removes its routines.
- Deleting a routine is immediate. There is no undo.
- The app keeps only the 20 most recent run records for each routine.
Frequency matters too. The DataCamp tester chose a weekly schedule on purpose, because running the same research every few minutes burns usage when nothing has changed.
xAI also warns about a broad listener, a routine that starts on events such as every new message in a channel, and names Slack messages and GitHub notifications as event triggers. A broad listener raises the chance of acting on irrelevant input.
How much should you trust it with your accounts?
Hand a first routine only work you can check afterward, in an account built for the Bot. Keep anything you could not undo behind an approval you read, or out of reach entirely.
The reason starts with the shared computer. xAI's docs say that files, browser sessions and command line credentials on it are available across your whole Bot roster, and they add: "Do not use separate Bots as a security boundary."
Each Bot does get its own screen, but the docs describe it as a separate work surface. Credentials reach that computer through takeover: for passwords, passkeys, two-factor codes and CAPTCHAs, the Bot hands you control. Open Agent Computer from a conversation to view the shared desktop. Take control. Complete the step, then return control. The session then persists, so other Bots can use the same signed-in session.
Deleting a Bot does not clean up after it. The same page says that deleting a Bot does not remove shared-computer files or browser sessions.
To remove access, the docs list several steps, among them two simple ones. Sign out of websites on the shared computer. Uninstall connectors and revoke their authorization in the source service.
Beyond cleanup, which actions need an approval depends on the tool, the risk and your rules. Auto Review is model-based, so xAI says it should complement least privilege rather than replace it.
Cursor says the same about its own classifier: it can make mistakes and is not a security boundary. That sentence is about Cursor's coding agent, and Grok Bot's docs do not repeat it.
An approval also controls only the proposed action, and does not reverse work already completed.
Responsibility sits with you. The page does not say whether xAI's consumer terms or Cursor's govern Grok Bot, so check your account. xAI's consumer terms say: "We are not responsible for User Content or Agentic Actions. You are responsible for User Content and Agentic Actions, including ensuring that it does not violate any applicable law or these Terms and any consequences, costs, or liabilities arising therefrom."
The record of what happened is thin. Action Recording and audit logs are Enterprise features. On an individual plan, the log that matters sits at the far end of each service. One reviewer notes that the far-end log names you rather than the Bot. A different review relays an early user's report that an unsubscribe job left some newsletters in place. That secondhand report still shows where to check: at the service.
Sort what you hand over by how well you could undo it.
What to hand a first routine
- Start here. Read public pages, read a scoped account, write drafts. Guardrail: xAI advises read-only tasks and draft outputs first.
- Behind approval. Send, publish, delete, purchase. Guardrail: an Ask first rule per action, read before you allow.
- Leave out. Banking, client accounts, anything you cannot undo. Guardrail: keep it off the shared computer entirely.
The third level is this guide's recommendation, drawn from the shared-computer rule. It is not a rule from xAI.
The docs back the first level with team guidance: "Sign the Bot's browser into accounts sized to the task, and sign it out of accounts it no longer needs. Use scoped service accounts where the source system supports them." That advice sits on the teams and enterprises page, and the approvals page repeats the scoped service accounts point.
Each service makes scoped accounts differently. Check its settings. The reviewer who flagged the far-end log goes further and suggests giving the agent its own identity.
To go further with connectors, see what MCP apps, connectors and plugins are.
FAQ
Is Grok Bot free?
There is a limited trial in the form of a usage credit with a seven-day window. Ongoing access comes with a paid Cursor plan or a linked SuperGrok subscription.
Can you choose which model Grok Bot uses?
No. A Cursor staff reply says you cannot pick the model for the Bot right now.
Can Grok Bot run commands on your own computer?
It runs commands on your own computer only if you allow it. The default is Ask every time, and the docs recommend Never allow unless a Bot has a specific reason to work on your local files.
Does Grok Bot remember everything?
It keeps stable preferences, role context and summaries. For consequential decisions, xAI says to ask it to check the current source instead of relying on memory.
Sources
- SpaceXAI, Introducing Grok Bot
- SpaceXAI, More plans for Grok Bot
- SpaceXAI Docs, Grok Bot overview
- SpaceXAI Docs, Get started
- SpaceXAI Docs, Skills and routines
- SpaceXAI Docs, Approvals, security, and privacy
- SpaceXAI Docs, Use the computer and apps
- SpaceXAI Docs, FAQ
- SpaceXAI Docs, Troubleshooting
- SpaceXAI Docs, Teams and enterprises
- SpaceXAI, Terms of Service
- Cursor, Plans and billing
- Cursor, Pricing
- Cursor, Privacy settings
- Cursor Docs, Run Modes
- Cursor Forum, Grok Bot spend cursor usage
- DataCamp, Grok Bot Tutorial
- Sorted Pixels, Grok Bot for Designers and Product Teams
- AI Tool Analysis, Grok Bot Review
- Build to Launch, AI scheduled tasks complete map
- Build to Launch, What are MCP apps, connectors and plugins