Grok Bot safety settings, in plain English
Grok Bot's help pages live on cursor.com and docs.x.ai. Here are the settings a new user should know, with links.
The docs say settings "depend on your account and rollout," so you may not see every one. Source.
1. Approval cards
When a Bot wants to do something that needs your OK, you see a card. Allow once lets it go ahead one time. Always allow can save a rule for next time. Deny blocks it. Checked
The onboarding page says to use Allow once while you learn, and Deny when it's not what you asked for. Source. The security page adds: nobody should approve an action "whose target or effect they can't identify." Source.
2. Your own "Ask first" rules
Go to Settings > General > Auto-review and add rules. Ask first rules always stop matching actions for you. Keep them narrow, like "ask first before sending any external email." Avoid broad rules like "allow everything in the browser." Checked Source.
Two catches from the docs: these rules are saved on the current computer, so a second computer needs its own. And Auto-review doesn't check everything, like memory writes and most settings changes. Checked
3. Your own computer
Bots work on their own cloud computer. They can run commands on your computer only if you allow it. The setting is Settings > Computer > Execution on this computer. The docs recommend Never unless a Bot has a specific reason to work on your files. Checked Source.
4. Surprise charges
When weekly usage runs out, on-demand usage can cost money. To cap it, open Settings > On-demand monthly limit in Grok Bot, or go to cursor.com/dashboard > Spending > Monthly Limit. The FAQ says a running task "can go a little past" the cap. Checked Source.
5. Plugins
Plugins connect Bots to things like Gmail and Slack. An installed plugin is available to every Bot you run. So only install what you need. Checked Source.
6. Passwords
Keep passwords and codes out of chat. Use the secure prompt when a Bot asks for a login. For sign-ins, the Bot hands you the computer and doesn't see your password. Checked Source.
7. Put rules in the Bot's Description
Lasting rules go in each Bot's Description (called Instructions on the phone). The docs say to put safety limits there "rather than in memory." Checked How to edit it. Our step-by-step.
Privacy and training
xAI's docs say Grok Bot uses your Cursor account's privacy settings, and training opt-out follows those settings. Source. We did not confirm the exact toggle name. Not checked