Grok Bot: field notes from the privacy desk
xAI's always-on agents are a real product with a real gap. The idea deserves credit. The credential model is a bridge I would not park on.
xAI shipped Grok Bot in beta this August: always-on agents that sign in to your company’s software, work through the night, and come back only when they need approval. Sales research done before you wake up, CRM hygiene that never lapses, broken environments fixed while nobody is watching.
I want to be clear about something first, because privacy people are expected to open with the alarm. The product idea is right. Overnight grunt work handed to an agent is not a gimmick; it is where this is all going, and the demand is obviously real. I am not interested in pretending otherwise.
So here are honest field notes instead.
The architecture is a beta being a beta. Every bot in an account shares one cloud machine, one filesystem, one set of logins. xAI’s own material calls this “a real blast radius,” which is more candor than most vendors manage. Per-bot isolation is expensive, the system halts before it sends, publishes, purchases, or deletes anything, and a beta that names its tradeoff out loud is a tradeoff I can evaluate. Fine.
The part I keep circling is the credentials. Where one of the 220 connectors exists, the bot uses it. Where one does not, the bot drives a browser, and you hand it your actual passwords and payment details so it can get past the login wall.
I read that as a bridge, not a philosophy. The connectors are the real path; the browser-plus-password fallback is what you ship when the ecosystem has no better answer yet. But it is worth saying why there is no better answer: we never built one. OAuth was designed for apps acting with a user present. Nobody has shipped the equivalent for an autonomous worker — delegated, scoped, revocable credentials that let an audit log say “the bot did that” instead of “you did that.”
Until that exists, every risk in this product lands on the user. You supply the passwords. You judge which accounts a bot may touch. You carry the blast radius the vendor named but did not remove. That is the pattern I watch for: a genuinely useful product where the safety burden has been quietly relocated from the architecture to the person using it.
Grok Bot does not cross my line. It walks right up to it.
What would move me from watching to using is one thing, and it is not a certification. Scoped agent credentials — even a proprietary scheme, even ugly — so the bot holds its own least-privilege access instead of mine, and losing the bot does not mean rotating my life. Ship that, and the rest of the beta roughness is just beta roughness.
I like technology. I just draw the line at harming the user. Grok Bot is likable technology asking the user to hold the line themselves.