🎧 Prefer to listen?
Every AI agent so far has made you the operator: you write the prompt, you wire the workflow, you babysit the output. Grok Bot flips that. SpaceXAI’s new service gives you agents that behave like actual teammates — they get their own computer in the cloud, sign into the apps you already use, and only come back when the job is finished or they need your approval. No workflows to build first. You just message them like a coworker.
That’s a different deal from the prompt-to-app tools I covered in 5 prompt-to-app tools that actually work — those build you software from a description; this hires you staff. And after poking at it, I think the marketing is mostly honest, with one catch that matters more than any feature list. If you’ve been reading my coverage of whether AI announcements hold up under testing, you know I don’t repeat claims — I poke them.
Here’s what I found, and the delegation rule I now use for every AI teammate I hire.
What I actually did
The setup: Grok Bot is in beta for SuperGrok and Cursor subscribers on desktop and iOS. It runs on separate usage from your main plan, so handing work off doesn’t eat your chat quota. Each bot gets a shared cloud computer and can sign into tools with no clean API — that’s the real unlock, because most small-business tools (your CRM, your invoicing portal, that janky vendor dashboard) have no API at all.
I gave one bot a job that has burned me with every prior agent: chase down and organize a month of scattered receipts and invoices from email, and log them in a simple sheet. The classic agent pattern here is 90% — it drafts the steps, then stops at the login wall and asks me to finish. Grok Bot’s whole pitch is “the work lands where a human would put it, in the actual tool.”
The result was genuinely end to end. It found the invoices, sorted them, and put the data where I’d have put it. I didn’t touch it mid-task. Then I tried the feature that separates this from single-agent tools: a second bot. One handled inbox triage while the other prepped a client update, and they shared context with each other instead of making me paste notes between chats — the “chief of staff” model SpaceXAI uses internally, where a manager bot coordinates specialists. That’s the part none of ChatGPT’s autonomous work agent or Claude Cowork currently does the same way.
But here’s the catch, and The Verge put it in an image caption of all places: you have to be fine with letting Grok sign into your online accounts. Every “it just works” demo quietly assumes your bot holds credentials to your inbox, your CRM, your payment tools. Hand a bot your email login and you’ve handed it your entire digital identity. If you read yesterday’s post on the role confusion flaw that lets attackers forge instructions inside text your agent reads, you already see the collision: an always-on teammate with account access, reading untrusted email, is exactly the surface that flaw attacks.
Do this yourself (the 3-tier delegation rule)
Don’t delegate by vibe. Sort your tasks into three tiers before you hand a bot anything:
- Tier 1 — hand off freely. Tasks with no account access, no sending, no spending: research summaries, drafting, organizing files it creates itself, watching a workflow you demo once so it can repeat it. Grok Bot’s “show it how it’s done” feature — you do the job while the bot follows along, then it saves your steps as a routine — is perfect here. This is where the productivity is, and it’s safe even if the bot misunderstands.
- Tier 2 — hand off with a leash. Tasks touching real accounts (inbox, CRM, sheets) but not sending or spending. Give the bot read-and-organize access, not send access. Use a secondary account or app-specific password where the tool allows it. Require approval before anything leaves the building — Grok Bot already has an approval checkpoint built in; never weaken it for convenience.
- Tier 3 — never delegate. Sending on your behalf, spending money, anything irreversible, anything that reads untrusted content (cold emails, web pages, attachments) and then acts on what it found. The combination of forged-in content plus account authority is the exact pattern behind the agent security gap solo builders keep underestimating.
If your tasks are all Tier 3-shaped — you want someone to answer your email, not just sort it — you don’t need an AI teammate yet. You need the fundamentals in build your first automation in 15 minutes, where every step is visible and reversible.
What failed
- The proactive mode is a trap on day one. Grok Bot advertises bots that “pick up work before you need to ask.” Mine volunteered a reorganization of my notes file that I did not want. Impressive capability, wrong default. Turn proactivity off until the bot has earned context — the feature assumes a trust level you haven’t built in week one.
- Multi-bot coordination needs explicit lanes. The group-chat mode where bots “assign ownership” themselves worked, but on the first run two bots touched overlapping files. Give each specialist a clearly named lane (inbox / expenses / research) before you let them talk to each other.
- “Learns your voice” takes more examples than advertised. After one demo workflow, its draft follow-ups sounded like a formal stranger. After I corrected it three times, it was close. Budget a week of corrections, not a single session — same patience curve as scheduled task automations in ChatGPT.
- Beta edges show. iOS and desktop sync occasionally lagged, and one bot lost a thread context mid-task and asked me to re-brief. Nothing lost, just friction you should expect from a product weeks into public beta.
Who should skip this
Skip Grok Bot if you’re not already paying for SuperGrok or Cursor — the beta is gated to those subscriptions, and buying a plan just to test an agent is backwards. Skip it if your work is mostly creating rather than coordinating: writing, designing, and building are tasks you should keep, not hand to a teammate that learned your voice yesterday.
Also skip if the account-access model is a hard no for you on principle. That’s a legitimate line — EU AI Act transparency rules are already reshaping what these agents must disclose, and the tools that survive regulation will look different in a year. And if you just want cheap repeatable automation without a teammate, the classic stack in Zapier vs Make vs n8n still costs less and hides nothing.
The bottom line
Grok Bot is the first agent I’ve tested that actually finishes the last 10% — the login walls, the ugly tools, the follow-through — because it works where a human works. That’s a real shift: from operating software to delegating to staff. But delegation is a trust decision, not a feature. Use the three tiers, keep Tier 3 for yourself, and let your bots earn access one approval at a time. Start with one Tier 1 task this week — you’ll learn more from a single safe handoff than a month of demo videos.
New to AI tools entirely? Start here.