Grok Bot · 第 07 课
审批、安全和常见问题
Approvals, security, FAQ
| English | 中文 | 怎么记 |
|---|---|---|
| approval | 审批 | 控制「准备做」的动作。已经做完的事,批准不能撤回。 |
| Allow once / Approve once | 允许一次 | 桌面是 Allow once,iPhone 是 Approve once。只放行这一次。 |
| Always allow | 总是允许 | 可存一条匹配规则。太宽的规则很危险。 |
| Deny | 拒绝 | 拦住这次动作。 |
| Auto Review | 自动审查 | 工具调用和电脑动作跑之前先评。有这个能力时才生效。 |
| Require Approval | 必须审批 | 匹配到的动作一律停下来问你。和 Always Allow 同时命中时,它赢。 |
| least privilege | 最小权限 | 只连这个流程需要的工具。先只读、先交草稿。 |
| secure secret request | 安全密钥请求 | 支持的连接弹出的遮罩输入。不是通用密码库。值不进对话、不给模型看。 |
| takeover | 接管 | 密码、通行密钥、两步验证、验证码、付款确认,你亲手在电脑上做。 |
| Legacy Privacy Mode | 旧版隐私模式 | Grok Bot 必须云端存数据,这个模式不支持。 |
| training opt-out | 退出训练 | 跟适用的 Cursor 账号和隐私设置走,不是 Grok Bot 另开一套。 |
| on-demand usage | 按需用量 | 套餐含每周用量;符合条件的账号可加按模型和 token 计费的用量。 |
| local computer | 你眼前的电脑 | 跟云电脑分开。默认每次问。没有明确理由就选永不允许。 |
先在请求里划边界 / Set a boundary in the request
Grok Bot is designed to complete work while keeping sensitive inputs and consequential actions under your control. Use approvals, secure handoffs, and clear Bot boundaries together. Tell the Bot which actions it can take and where it must stop, for example: reconcile the campaign data and draft a recommended budget change; do not change the campaign or message the agency; ask for approval after showing the current value, proposed value, and expected impact. Prefer explicit boundaries for sending messages or invitations, publishing content, purchases and financial transfers, deleting or overwriting data, changing permissions, production changes, and accepting legal terms. An approval controls the proposed action. It does not reverse work already completed.
Grok Bot 要把活干完,同时把敏感输入和后果大的动作留在你手里。审批、安全交接、清楚的 Bot 边界,三样一起用。告诉它能做什么、必须停在哪。比如:对上活动数据,起草一份预算修改建议;不要改活动,不要给代理发消息;先把现值、拟改值、预期影响摆出来再请批。这些事最好写死边界:发消息或邀请、发布内容、采购和转账、删除或覆盖数据、改权限、改生产、接受法律条款。审批管的是「准备做」的动作,已经做完的事撤不回。
审一个动作 / Review an action
When an action needs approval, the conversation shows the proposed operation and its inputs. Review the target, scope, and values before approving. On desktop, Allow once lets the Bot continue with that action and Deny blocks it. Always allow can save a matching rule. On iPhone, the equivalent controls are Approve once and Deny. Do not approve an action whose target or effect you cannot identify. Ask the Bot to explain it in plain language or produce a draft first.
需要审批时,对话会显示拟操作和它的输入。先看目标、范围、数值,再批。桌面:Allow once 放行这一次,Deny 拦住。Always allow 可存一条匹配规则。iPhone 对应的是 Approve once 和 Deny。目标或效果看不清,就别批。让它用白话解释,或先出一份草稿。
配置 Auto Review / Configure Auto Review
When Auto Review enforcement is available, Grok Bot evaluates tool calls and computer actions before they run. Open Settings → General → Auto-review to add rules. Require Approval rules always stop matching actions for you. Always Allow rules let matching actions proceed only when the automated review does not identify another reason to stop. If both kinds of rule match, Require Approval wins. Write narrow rules around a known action and scope, such as requiring approval before sending any external email or changing a production dashboard, or always allowing git status in /workspace/reports. Avoid broad rules such as “allow everything in the browser.” Websites and tool behavior change over time. Auto Review is model-based and should complement, not replace, least privilege and explicit approval boundaries. Personal Auto-review rules are stored on the current desktop and synced to its Grok Bot computer. Verify them separately on another desktop installation.
Auto Review 强制可用时,Grok Bot 会在工具调用和电脑动作跑之前先评。打开 设置 → General → Auto-review 加规则。Require Approval 匹配到就一律停下来问你。Always Allow 只有自动审查没发现别的该停的理由时,才放行。两种都命中,Require Approval 赢。规则写窄,围着已知动作和范围,比如对外发邮件或改生产看板必须先批,或允许在 /workspace/reports 里跑 git status。别写「浏览器里什么都允许」。网站和工具行为会变。Auto Review 是模型做的,用来补最小权限和明确审批,不能替代它们。个人 Auto-review 规则存在当前这台桌面,并同步到它的 Grok Bot 电脑。换一台桌面安装,要另行核对。
密码和验证码自己输 / Enter passwords and codes yourself
For passwords, passkeys, two-factor codes, CAPTCHAs, and payment confirmations, the Bot should hand you control of the computer. Open Agent Computer, take control, complete the sensitive step, return control, and tell the Bot to continue. Do not send a password or one-time code in ordinary chat. If the Bot presents a secure secret request for a supported connection, enter the value in that request. It is not a general-purpose password manager. The value is masked, excluded from the transcript, and not shown to the model.
密码、通行密钥、两步验证码、验证码、付款确认,Bot 应把电脑控制权交给你。打开 Agent Computer,接管,做完敏感那一步,交回控制,让它继续。别在普通聊天里发密码或一次性验证码。支持的连接若弹出安全密钥请求,就在那一栏填。它不是通用密码库。值是遮住的,不进对话记录,也不给模型看。
管好你眼前的电脑 / Control access to your local computer
The shared Grok Bot computer runs in the cloud. Access to the Mac or Windows computer in front of you is a separate capability. In Settings → General → Agent → Execution on Local Computer, choose whether local commands always require approval, are always allowed, or are never allowed. The default is Ask every time. Use Never allowed unless a Bot has a specific reason to work on your local files. These settings do not prevent the Bot from using its cloud computer.
共用的 Grok Bot 电脑跑在云上。碰你眼前这台 Mac 或 Windows,是另一项能力。在 设置 → General → Agent → Execution on Local Computer,选本地命令是每次都要批、总是允许、还是永不允许。默认是每次问。没有明确理由让 Bot 动你本地文件,就选永不允许。这些设置不阻止它用自己的云电脑。
共用电脑不是安全边界 / The shared-computer boundary
All of your Bots share one cloud computer assigned to your user account. Files, browser sessions, and command-line credentials on that computer are available across your Bot roster. Do not use separate Bots as a security boundary. Sign out of a service when it should no longer be available. Remove sensitive temporary files after the work is complete. Delete a connector or revoke its authorization in the source service when access is no longer needed. Do not treat this user assignment as a guarantee broader than Cursor’s published security documentation.
你名下所有 Bot 共用一台挂在用户账号上的云电脑。上面的文件、浏览器会话、命令行凭证,花名册里大家都拿得到。别把「分开几个 Bot」当成安全边界。某个服务不该再用,就登出。活干完,敏感临时文件删掉。连接器不用了,卸掉,并在源服务里撤销授权。别把「按用户分配」理解成比 Cursor 已公布安全文档更宽的保证。
分享链接也不是安全边界 / Sharing a Bot is not a security boundary
A public share link lets others copy the Bot’s configuration. It does not share your computer or logins. Still, do not put secrets, customer data, or internal URLs in a Bot you share. Shared Bots are created by other users, not by SpaceXAI; adding one accepts the third-party bot terms.
公开分享链接让别人复制 Bot 的配置,不会分享你的电脑或登录。但你要分享的 Bot 里,别放密钥、客户数据、内网地址。别人做的 Bot 不是 SpaceXAI 做的;加进去等于接受第三方 Bot 条款。
账号、数据和收权限 / Cursor account, data, and removing access
Grok Bot uses Cursor authentication and account data settings. It requires data storage and does not support Legacy Privacy Mode. Privacy and data-sharing choices are managed through Cursor account settings and, when required, the Grok Bot access flow. Training opt-out follows the applicable Cursor account and privacy settings. Review the current Cursor Privacy Policy and security information for contractual details. Organization administrators can restrict local-computer execution and may provide managed setup for the cloud computer; available controls depend on the organization’s rollout and plan. When a project or login should no longer be available: pause or delete related routines; sign out of websites on the shared computer; uninstall connectors and revoke their authorization in the source service; remove sensitive project files from /workspace; hide or delete Bots that should no longer appear; use the account settings flow if you need to delete the Cursor account. Deleting a Bot does not remove shared-computer files or browser sessions. Backend retention and account deletion follow the applicable Cursor terms.
Grok Bot 用 Cursor 认证和账号数据设置。它必须存数据,不支持 Legacy Privacy Mode。隐私和数据分享走 Cursor 账号设置,需要时再走 Grok Bot 访问流程。退出训练跟适用的 Cursor 账号和隐私设置走。合同细节看当前的 Cursor 隐私政策和安全说明。组织管理员可以限制本地电脑执行,也可能提供云电脑的托管配置;能用哪些控件取决于组织的上线和套餐。某个项目或登录不该再用:暂停或删除相关 routine;在共用电脑上登出网站;卸掉连接器并在源服务撤销授权;从 /workspace 拿走敏感项目文件;隐藏或删除不该再出现的 Bot;要删 Cursor 账号,走账号设置流程。删 Bot 不会清掉共用电脑上的文件或浏览器会话。后台留存和删账号按适用的 Cursor 条款。
最小权限 / Use a least-privilege setup
Connect only the tools a workflow needs. Use scoped service accounts where the source system supports them. Start with read-only tasks and draft outputs. Keep sending, publishing, purchasing, deletion, and production changes behind approval. Review installed connectors and active routines regularly. Pause a routine when its source system or expected workflow changes. Preserve source links and an action log for important decisions.
只连这个流程需要的工具。源系统支持的话,用范围收窄的服务账号。从只读任务和草稿产出开始。发送、发布、采购、删除、改生产,放在审批后面。定期看已装连接器和正在跑的 routine。源系统或预期流程变了,就暂停 routine。重要决定留下源链接和操作日志。
常见问题(文档 FAQ,不重复前面已写清的细节) / FAQ
Bots differ from an AI assistant because they use a persistent cloud computer, connected tools, websites, and files to complete work—not only answer questions. Talk to them in the macOS or Windows desktop app, or the iOS companion; the same Bots and conversations sync across signed-in devices. Closing the app, laptop, or iPhone does not stop a background turn or routine. Several Bots can work at the same time; each has its own screen, and one Bot runs one computer-use task on that screen at a time. Grok Bot can use many browser-based tools, including services without a dedicated connector, but a site may still block automation, require a new login, present a CAPTCHA, or require a human. The Bot should hand those steps to you rather than bypassing them.
Bot 跟普通 AI 助手的差别:它用持久云电脑、已连工具、网站和文件把活干完,不只是回答问题。在 macOS / Windows 桌面 App 或 iOS 配套 App 里跟它说话;同一套 Bot 和对话会在已登录设备间同步。关 App、合笔记本、锁屏 iPhone,后台这一轮和 routine 都不会停。几个 Bot 可以同时干;各自一块屏幕,一个 Bot 在自己屏幕上一次只跑一件电脑操作。很多基于浏览器的工具它都能用,包括没有专属连接器的服务;但网站仍可能拦自动化、要重新登录、出验证码、或要真人。这些步骤应交给你,而不是绕过去。
Availability and billing depend on the account and plan. Eligible plans in the FAQ match Get started: SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra, and Cursor Teams Standard and Premium. Subscriptions include weekly usage; eligible accounts can add on-demand usage billed from model and token cost. If you have both a Cursor and a SuperGrok subscription, Grok Bot uses whichever has more usage. Review the current access page or Cursor pricing for current terms. Self-serve Cursor Teams Standard and Premium seats include Grok Bot. Enterprise access is rolling out; contact the Cursor account team. Platforms at initial launch: macOS on Apple silicon and Intel; Windows on x64 and Arm64; iPhone on iOS 18 or later. Linux desktop, Android, and iPad are not supported.
能不能用、怎么计费,看账号和套餐。FAQ 的名单和上手篇一样:SuperGrok Plus、SuperGrok Heavy、Cursor Pro+、Cursor Ultra、Cursor Teams Standard 和 Premium。订阅含每周用量;符合条件的账号可加按模型和 token 计费的按需用量。同时有 Cursor 和 SuperGrok 时,Grok Bot 用额度更多的那份。当前条款看访问页或 Cursor 定价。自助的 Cursor Teams Standard / Premium 席位包含 Grok Bot。企业版在滚动开放;问 Cursor 客户团队。首发平台:macOS 苹果芯片和 Intel;Windows x64 和 Arm64;iPhone 要 iOS 18 或更高。Linux 桌面、Android、iPad 首发不支持。
不确定:介绍文还写了 SuperGrok、Cursor Pro。FAQ 和 Get started 没有。以 docs.x.ai 为准。
A skill describes how to perform a task. A routine assigns a workflow to one Bot and tells it when to run. Test the skill on a real one-time task before turning it into a routine. When Teach a task is available, record one browser workflow; the recording is limited to ten minutes and the rollout may be gradual. What a Bot remembers, how sharing and deletion work, and the shared-computer rule are covered in earlier lessons; for important decisions, ask the Bot to check the current source rather than relying on memory.
skill 描述怎么干。routine 把流程交给一个 Bot,并告诉它何时跑。先在一次真任务上测 skill,再做成 routine。有 Teach a task 时,录一段浏览器流程;最多十分钟,功能可能分批开放。Bot 记得什么、怎么分享和删除、共用电脑的规矩,前面几课写过。重大决定让它查当前来源,别只靠记忆。
读完能记住的三句话
Approval gates the next action; it does not undo work already done.
审批拦住下一步;已经做完的事撤不回。
Separate Bots are not a security boundary; take over for secrets; default local access to never allowed.
分开几个 Bot 不是安全边界;秘密你来接管;本地权限默认选永不允许。
Eligible plans and weekly usage follow current docs and pricing; Linux desktop, Android, and iPad are not in the first launch.
套餐和每周用量看当前文档和定价;Linux 桌面、Android、iPad 首发没有。