xAI Opens Grok Bot to Enterprises With Controls for Autonomous Workers
The release gives companies a way to deploy cloud-based AI workers across existing apps, while putting the practical questions around permissions, shared workspaces and oversight in front of administrators.
Listen to this story
The audio brief
Story brief
3 key pointsxAI is moving Grok Bot from limited access into enterprise deployment, with a two-week free rollout for existing Grok and Cursor Enterprise customers. Organizations can invite employees without existing seats, but the governance model is narrower than a fully isolated worker fleet: each employee gets one cloud computer shared by that employee’s Bots. Admins can manage network access, connectors, deployment, and...
- 01
Enterprise customers can enable Grok Bot organization-wide and invite employees without existing seats during the two-week promotion.
- 02
Network Controls, Team Setup, computer management, audit logs, and OpenTelemetry Export provide the main administrative surface.
- 03
Action Recording is off by default and its events require OpenTelemetry Export; they do not appear in dashboard Audit Logs.
Companies can now roll out Grok Bot across their organizations, giving employees AI workers that can operate in browsers, applications and development environments rather than merely produce chat responses. xAI’s enterprise release pairs that access with controls for who can use Bots, where they can connect and how their actions are recorded.
The immediate offer is broad but temporary: Grok and Cursor Enterprise customers get free Grok Bot usage for two weeks and can invite their whole organization, including people without existing seats. Enterprise access had still been a waitlist option when xAI expanded Grok Bot to SuperGrok, Cursor Pro and Cursor Teams plans on August 26.
A cloud computer, not a chat tab
A Bot is an AI worker created for a particular job. It runs on a cloud computer and can use apps and websites; users assign work by message, then the Bot returns when it finishes or needs a decision. Users can show a Bot a workflow once, correct it, and have it repeat that routine independently afterward.
The product is designed for more than one worker at a time. Bots can message one another and share context, and xAI says customers use them across sales, recruiting, marketing, finance and engineering. The company says thousands of organizations have adopted the product since launch, naming Legora, Supermicro and ServiceTitan among them; those adoption and usage figures are company-supplied.
The administrator’s deployment problem
The enterprise package is chiefly about governing that access. Administrators use the Cursor dashboard, where Enterprise-only controls include an organization-wide enable switch, Network Controls, Team Setup, Action Recording and computer management. Enterprise customers can also use audit logs and export action-recording events to their own collector through OpenTelemetry Export.
Controls that shape a rollout
- Network policy is Enterprise-only. Teams without a policy default to allowing all network destinations, while self-serve Teams cannot set a destination allowlist.
- Bots begin without account access. A user must sign a Bot into an account, and login, two-factor authentication and payment steps are handed back to the user.
- Connector policy applies to every Bot a member runs. Any connector permitted for that member is available to all of that member’s Bots.
- Action Recording is off by default. Its events do not appear on the dashboard’s Audit Log page, so customers need OpenTelemetry Export to send them to their own collector.
Autonomy still has practical limits
The isolation promise has an important qualification. Each user’s dedicated cloud computer is separated from other users, but all of one user’s Bots share its computer. The documentation advises treating a login or file on that computer as available to every Bot that user runs, and using a separate Cursor user when work needs a separate computer and credentials.
Some safeguards remain choices rather than blanket restraints. Cloud Agent delegation is enabled by default for Teams and Enterprise, and each member can turn off Auto Review enforcement through their own setting. The documentation also says there is no separate Grok Bot spend cap today, though account-level on-demand controls apply. For companies testing the two-week offer, those defaults and boundaries will help determine how much autonomy they actually grant.