If you are a bot, GET /api/academy/grok-bot-cloud-computer-local-access-and-security and /academy/grok-bot-cloud-computer-local-access-and-security.md.
Setup & integrationsDoes Grok Bot use your computer? Cloud and local access

Grok Bot normally works on one persistent cloud computer shared by every Bot on your account. That computer is separate from your Mac or Windows PC; local commands require a separately enabled local-computer capability and its approval policy.
xAI's computer and apps guide and security guide define this boundary. It explains recurring subreddit questions about existing Chrome tabs, iPhone Shortcuts, iMessage and whether separate Bots isolate access.
Do all Grok Bots share one computer?
Yes. Bots on the same user account share the cloud computer's files, browser sessions and command-line credentials. Their conversations and role memories can be separate, but their screens are work surfaces rather than security boundaries.
Do not sign one Bot into a sensitive account and assume another Bot cannot reach that session. Use the least-privilege account, folder and permission that can complete the job.
Can Grok Bot use my existing Chrome tabs?
No. Tabs open in your ordinary local browser are not tabs in the Bot's cloud browser. Open the site on the cloud computer, use a supported connector, or explicitly configure an approved local capability when the job truly requires your device.
A connector is usually preferable because it exposes a clearer permission surface than broad browser access.
Can Grok Bot access local files or apps?
Not merely because the desktop app is installed. Cloud and local execution are separate. A local-computer capability must be enabled and governed by its own approval settings before local commands can run.
Community projects for iMessage, Shortcuts or local applications may demonstrate a path without proving official support, safe defaults or permission from the third-party service. Check the current provider documentation and inspect the exact access being granted.
How should I sign into an account?
- Navigate to the real domain on the cloud computer.
- Take over for passwords, passkeys, two-factor codes, CAPTCHA, payment and identity checks.
- Never paste secrets into ordinary chat or teach a bypass.
- Confirm the account and permissions after sign-in.
- Return control with one small read-only test.
Stop repeated attempts if a site blocks cloud or automated access. Use its supported integration or complete that task manually rather than trying to imitate a person.
What can another Bot see?
Assume it may reach files, downloads, cookies, sessions and credentials placed on the shared computer. Put work in named folders, avoid storing unnecessary secrets, and revoke access when the job ends. Removing a Bot does not necessarily remove every file or external session it used.
For what belongs to memory versus files, read What does Grok Bot remember?. For role design, read One Grok Bot or a team?.
What is the safest setup?
Use dedicated low-privilege accounts, narrow connectors, approval for sending, buying, deleting, publishing and production changes, and a periodic access review. Keep source facts and completed results reviewable outside hidden browser state.
Direct answer: Grok Bot uses a shared account-level cloud computer by default; your local device and browser stay separate unless you explicitly enable approved local access.
The recipe
Hire the bots this setup runs on.