On August 11 the agent teammate stopped being a framework and became a product with a price tag. Here is the whole guide in one picture.

The path
Seven posts, four moves
ORIENT CHOOSE BUILD RUN 1 2 3 4 5 6 7 the map lineage sandbox the fleet teach mode trust zone the $300 what you are buying pick your blast radius make it work safely, and worth it
Read left to right, or jump to the move your week needs.

The parts

Part 1. Grok, X, Cursor, Grok Bot: The Missing Map
Nine products, four live brand names, two accounts you link by hand, four billing rails, and no official comparison page anywhere. Start here if you are not sure what you are buying.

Part 2. Hermes and OpenClaw Did This First. Grok Bot Made It Plug and Play.
Persistent agents are not new. Two open-source projects shipped them earlier, one of them before OpenClaw existed. What Grok Bot removed, and what that convenience costs you in sovereignty and lock-in.

Part 3. Anthropic Destroys the Sandbox. Grok Bot Keeps It Forever.
The category split into two opposite security architectures and both vendors documented their own choice. One is built so no credential survives a session. The other is built so every credential survives every session. Choose deliberately.

Part 4. Your Second Grok Bot Should Be a Chief of Staff.
The fleet architecture, the advisor-first move, what a real five-bot roster looks like, and why scoping a bot is the same skill as writing a job description.

Part 5. Don't Prompt Grok Bot. Record 10 Minutes and Let It Watch.
Teach mode, the skill-versus-routine distinction that stops beginners stalling, and the iteration loop that separates working bots from abandoned ones.

Part 6. Every Grok Bot Shares One Computer. And Every Login on It.
The governance post. Your bots are not a security boundary, the vendor says so plainly, and the marketing says the opposite. How to scope risk at the connection level instead.

Part 7. One Grok Bot Paid Its Own Salary. Another Got Fired.
The honest economics. What the wins have in common, what the failures have in common, and whether you should buy now or wait.

Where to start

Confused about what to buy17
Already have access, want it working456
You run the company367
You already run OpenClaw or Hermes23
Start from zeroPrologue14567

What actually shipped

Your account gets one persistent cloud computer with a browser, a filesystem and a terminal. You create bots on it, give each a role, and they sign into your tools with your credentials. They work unattended, message each other, hand work between them, and report back in a group chat. You reach them from your phone. Closing your laptop does not stop them.

The price is $200 a month through Cursor Ultra, $300 through SuperGrok Heavy, or $120 per seat on Cursor Teams Premium, with token usage billed on top. There is no meaningful free tier. That pricing, more than any capability question, is what decides whether this is for you yet.

The three rules, found twice

Here is why this guide exists rather than another launch review. Two days after release, Matt Van Horn swept X, Reddit and YouTube for every workflow people were actually running, and found three properties present in all the ones that worked. Independently, SpaceXAI's own documentation states the same three things. Neither cites the other. When practitioners reverse-engineer a discipline and the vendor's engineers write it down separately, that is about as close to a settled answer as a nine-day-old product gets.

One job per bot. Van Horn: "the single do-everything bot is the beginner mistake the follow-up threads keep correcting." The docs: a job like General Helper "gives the Bot less guidance and makes its saved context harder to reuse."

Taught, not prompted. Van Horn: "the winners recorded themselves doing the task once and corrected the second run. Nobody wrote a 500-word system prompt." The docs ship teach mode, which learns "workflows from live demonstration."

Draft and approve at the money-or-send step. Van Horn: "every workflow that people trust enough to keep running has a human gate." The docs: all eight of the vendor's own reference roles prepare work and withhold the action. Sales Outbound explicitly does not send.

Everything else in this guide is downstream of those three.

Fig. 1
Found twice, from opposite directions
The same three rules, twice NEITHER CITES THE OTHER FIELD REPORTS VENDOR DOCUMENTATION 1 "The single do-everything bot is the beginner mistake." "General Helper... makes its saved context harder to reuse." 2 "Nobody wrote a 500-word system prompt." Teach mode: "learn workflows from live demonstration." 3 "A human gate at the money-or-send step." All 8 reference roles prepare work and withhold the action. Practitioners reverse-engineered it in nine days. The vendor's engineers wrote it down separately.
When both sides of a new product arrive at identical rules without coordinating, that is the closest thing to a settled answer available.
Sources: Van Horn field sweep, August 13, 2026; docs.x.ai bots and use-cases pages

Around the guide

Four posts on the Playbook sit alongside this guide. The first three predate it and read as the prologue. The fourth is adjacent: infrastructure your fleet depends on, rather than the fleet itself.

xAI Shipped the Agent Teammate. It's Called a Bot.
Written on launch day, August 11. The argument that the boundary between an employee and an agent had just become a login. Everything in this guide is the working-out of that sentence.

Grok Bot Week One: 90,000 Emails and a Chief of Staff Bot.
The field report from the first nine days: what people actually ran, what broke, and the org chart that emerged. Part 4 turns that observation into a method.

xAI Just Made It a Three-Horse Race.
Background on Grok 4.6, the model underneath the bots, released the day after launch at $2 per million input tokens. Useful if you want to know what is doing the thinking.

GitHub Went Down. Cursor Shipped Origin the Same Day.
Not about operating bots, but about what they now depend on. A code-host outage stops being an inconvenience the moment your agents work while you sleep.

Why this matters past the product

Grok Bot will not be the last product in this category, and it may not be the one you end up running. Peter Yang's bet is the reasonable one: "OpenAI, Anthropic, and others will soon follow Grok Bot's steps with the persistent cloud computer." Nous shipped a competing bot mode 51 hours after launch. The specific vendor is the least durable thing here.

What is durable is the operating model. One job per agent. Teach by demonstration. Gate the actions that spend money or speak on your behalf. Give an agent that acts its own identity rather than yours. Those rules will outlive this product, and they are the same rules that separate a Level-3 agent from a chatbot with extra steps.

Hiten Shah put the shift better than anyone: "people are already writing job descriptions, training new hires, adding managers, and firing bad fits with Grok Bot. Software adoption is starting to look a lot like company building." If that is true, and the receipts suggest it is, then the constraint on your AI programme was never model capability. It is whether you can write a good job description.

Staffed, not installed.

Your first bot team, governed.

Book a free Diagnostic: 30 to 45 minutes, no deck, no pitch. We map which of your workflows a bot team could run this quarter, and the credential and approval guardrails to run it safely.

Book the Diagnostic →
Sources
1Grok Bot launched in early beta on August 11, 2026 for SuperGrok Heavy, Cursor Ultra and Cursor Teams Premium subscribers. x.ai
2SpaceXAI documentation: "Every Bot on your account uses the same computer... Browser cookies and signed-in sessions are shared." "The screens are separate work surfaces, not separate security boundaries." docs.x.ai
3SpaceXAI ships eight reference bot roles, each scoped to prepare work with the acting step withheld. docs.x.ai
4Matt Van Horn's cross-platform sweep of X, Reddit and YouTube, August 13, 2026, identifying three properties common to every working setup. x.com
5Corporate timeline: SpaceX acquired xAI February 2, 2026; the AI unit rebranded SpaceXAI in July 2026; SpaceX closed its $60B acquisition of Anysphere (Cursor) on August 14, 2026. techcrunch.com
6Anthropic Claude Cowork architecture: "Each session gets its own sandbox, created when the session starts and destroyed when it ends"; "Connector authorization tokens never enter the sandbox." support.claude.com
7Miles Deutscher, "Grok Bot: The Ultimate Guide", August 18, 2026. x.com
John Tan
John Tan

Founder and CEO of nativefirst.ai. Embeds with scaling founders and CEOs to ship Level-3 agents and AI workflows in production.