Grok Bot, from SpaceXAI (formerly xAI) and run on Cursor's cloud, gives you Bots: AI teammates with a name, a job, and a persistent cloud computer with a browser, terminal, and files. You message them from desktop or phone, or in Slack for Team Bots, and they finish work in your real tools, including websites with no clean API. For that work it is very good. Boring runs the work a company answers for: agents owned by a team, started where work arrives, held to the exact actions they were granted, and reviewed by the person assigned to decide. Use both. This page shows where the line sits.
Updated
If the job needs a computer, get Grok Bot. Its Bots work in a real browser and terminal on a cloud computer, so they finish tasks on portals that have no clean API, and they hand passwords, two-factor codes, and payments back to you. Team Bots, in public beta, answer a whole team in the app or in Slack, using each asker's own account wherever a plugin needs a sign-in. There are templates and a Marketplace, and Enterprise adds SCIM, network allowlists, enforced Auto-review, and Action Recording on top of Cursor SSO. Boring answers a different question: who operates a workflow when the company has to answer for it. Its agents belong to a workspace, start from webhooks, inbound email, forms, and app events as well as schedules, call only the exact actions they were granted, and wait for the reviewer you assign, who can fix the proposed call before it runs. Give each person a Bot. Run what the company answers for through Boring.
| Capability | Boring AI | Grok Bot |
|---|---|---|
| // shape of the product | ||
| What it is | A console where a team builds, operates, and reviews automation agents. | In SpaceXAI's words, "AI teammates with names, jobs, and context that compounds over time", each working on a persistent cloud computer. |
| Who owns and directs it | A workspace: roles, private or workspace visibility, live co-editing, and versioned definitions where every change is a diff you can roll back. | Personal Bots belong to one person. Team Bots (public beta) are shared, but each teammate's chat is private and routines are personal: "No routine runs for the whole team at once." |
| Where you talk to it | The console and the workspace assistant (⌘J), a native mobile companion for approvals (store release pending), and email or Slack notifications. Not a chat-app product. | A real strength: desktop apps for macOS, Windows, and Linux, iPhone, iPad, and Android, live voice chat, and Slack for Team Bots, which can each have their own Slack app. |
| A computer of its own | No computer use or signed-in browsing. Agents act through connected tools and can load public web pages. | A persistent cloud computer with a browser, terminal, and files, for sites with no connector. Passwords, two-factor codes, CAPTCHAs, and payments are handed back to you. |
| // judgment and control | ||
| What waits for a person | New agents start with every connected action waiting for approval. Owners loosen it to writes only or auto-approve eligible actions they trust, such as reads; an action Boring can't classify counts as a write. | Approval cards with Allow once, Always allow, or Deny, backed by Auto Review, "an independent review model" that can let an action proceed, ask for approval, or deny it. |
| Who decides, and what they can change | An assigned reviewer in a shared Tasks inbox can approve, modify the proposed call, or reject it, and the agent's owner or an admin can reassign it. Reviews can carry due dates, reminders, and a configured overdue outcome. | The member in the conversation answers the card, and email or Slack drafts can be edited before sending. Editing any other proposed action, or routing it to a named reviewer with a due date, is not specified in SpaceXAI's public docs. |
| Hard limits on actions | Exact-action grants are enforced in code: an agent without the send action cannot send, whatever its instructions say. | No access by default, a team connector policy that allows or blocks each connector, and network allowlists on Enterprise. Withholding one action inside an allowed connector is not specified in SpaceXAI's public docs. |
| Rules and procedures | Numbered instructions run as an enforced plan, one step at a time, and a step can require evidence: a saved artifact or a successful tool receipt. | Team Rules and Auto-review rules are written in natural language. In the Grok Bot 101 guide's words: "With Grok Bot, the rules are a prompt." |
| // starting, recovering, and records | ||
| How work starts | Schedules, webhooks, inbound email, public forms, SaaS app events, the Chrome extension, the workspace API, MCP clients, and other agents. | Chat, schedules, and events from Cursor account integrations, such as a Slack message or a GitHub notification; Team Bots add a Slack channel listener. An inbound webhook, public form, email address, or API that starts a routine is not specified in SpaceXAI's public docs. |
| When something fails | Resume eligible failed runs from the last completed step; in a numbered step plan, when an action's outcome is uncertain, Boring blocks automatic repetition instead of guessing. Failure reasons are classified, with the provider's reference ID. | Each routine shows recent success and failure history, and Test run performs real work. The docs advise "Make retries idempotent where possible"; platform retry or resume from a failed step is not specified in SpaceXAI's public docs. |
| Record of the work | One shared trace per run: reasoning, tool calls, inputs and outputs, and approvals. Tool payloads are kept 90 days; the outcome, output, and step list stay. An agent's latest 100 runs export as CSV or JSON. | The conversation shows the Bot's work, and the app keeps the 20 most recent run records per routine. On Enterprise, Action Recording (off by default) keeps sanitized metadata for every tool call for 90 days, exportable over OpenTelemetry. |
| The model | Claude Sonnet 5.5 by default, managed GPT, Gemini, and Grok with no key, or your own Anthropic, OpenAI, Google, OpenRouter, or compatible-endpoint key. | "Cursor manages model selection. There is no customer-facing model picker." An Enterprise model allowlist exists, and SpaceXAI notes "enforcement is not guaranteed". |
| Price and access | Early access, on design-partner terms, with white glove if you want the agents built and operated with you. | In beta. Included with Cursor Pro ($20 a month as of October 2026), Pro+, Ultra, and Teams, or a linked individual SuperGrok or X Premium+ plan. Usage is a weekly grant, then on-demand billing through Cursor when on-demand is on. |
Details about Grok Bot come from SpaceXAI's documentation at docs.x.ai, its Grok Bot guides and news posts, and Cursor's Grok Bot plans and pricing pages, checked 3 October 2026. Grok Bot is in beta and Team Bots are in public beta, so details change quickly. Where the docs don't specify something, we say so rather than call it missing. If anything here is out of date, tell us and we'll fix it.
SpaceXAI describes Bots as "AI teammates with names, jobs, and context that compounds over time", and the product is built around the person who runs them. All of one person's Bots share a single cloud computer, with its files, browser sessions, and logins, and the docs are direct about what that means: "Do not use separate Bots as a security boundary." Team Bots, in public beta since 28 September, add one Bot the whole team talks to, with team memory, private notes for each person, and, once the owner adds it, its own Slack app. When a plugin needs a sign-in, a Team Bot uses the account of whoever is asking, so it "never lends one person's access to another." For shared questions, that is a thoughtful design.
Recurring work stays personal, though. A routine on a Team Bot "runs as them, reports in their chat, and only they can see or change it. No routine runs for the whole team at once." A company workflow has a different shape. The refund queue, vendor onboarding, and the Monday customer report each have several people who edit them, review what they did, and answer for the result. Boring puts agents in a workspace, with roles, private or workspace visibility, live co-editing, and one shared record per run. Every change to a definition is a versioned diff you can roll back.
Grok Bot's approval model is published and layered. When an action needs approval, the conversation shows the proposed operation and its inputs, and the member chooses Allow once, Always allow, or Deny. Behind those cards, Auto Review checks shell commands, plugin calls, computer use, automation writes, and delegation, then lets an action proceed, asks for approval, or denies it. Members add Ask first and Allow automatically rules, Ask first wins a conflict, and Enterprise admins can enforce Auto-review with locked team rules. Email and Slack drafts arrive as editable cards. In a Team Bot conversation where nobody can answer an approval card, the docs say the Bot "runs without Auto-review and stays within the permissions it was set up with, unless your team requires Auto-review."
Boring starts stricter and routes the decision. New agents start with every connected action waiting for approval; owners loosen that to writes only, or auto-approve eligible actions they trust, such as reads. Each request leads with the exact tool call and its scrubbed arguments, goes to the reviewer you assign, and can carry a due date, reminders, and an overdue outcome of reject or skip. The reviewer can approve, reject, reassign, or modify the exact arguments before the call runs. SpaceXAI's public docs don't specify editing a proposed action other than an email or Slack draft, or assigning a request to a named reviewer with a due date.
Grok Bot has hard layers that don't depend on a model. A Bot has no access by default and acts only with accounts the member signs it into, an approval card holds an action until the member answers, teams set a connector policy and a ceiling on local execution, and Enterprise adds network allowlists. Above those layers, the standing rules are natural language, and SpaceXAI's Grok Bot 101 guide is candid about it: "You are trusting the model to follow what you wrote… With Grok Bot, the rules are a prompt." Its security docs say Auto Review "is model-based and should complement, not replace, least privilege", and that it "does not review every side effect. Memory writes and most settings changes are examples."
Boring moves more of the policy into code. Exact-action grants decide what an agent can call at all, so a send action can be withheld entirely rather than prompted against. Numbered instructions run as an enforced plan: one step at a time, no skipping ahead, each step marked complete. A step can require evidence before the plan moves on, such as a saved artifact or a successful tool receipt for an exact target. The model still uses judgment inside a step; what it may call, and in what order, is not left to it.
A Grok Bot routine runs "on a schedule or, where supported, after an event". Cursor account integrations can start one from a Slack message or a GitHub notification, Team Bots add a Slack channel listener, and Test run executes a routine on demand. That covers a great deal of personal and engineering work. A company's work also arrives as a webhook from another system, an inbound email, a form a customer submits, or an event in a SaaS app. Boring starts runs from all of those, plus schedules, the Chrome extension, the workspace API, MCP clients, and other agents. SpaceXAI's public docs don't specify an inbound webhook, public form, email address, or API that starts a routine.
When a Boring run breaks, its saved plan and progress stay, and eligible failed runs resume from the last completed step. In a numbered step plan, when a write's outcome is uncertain, Boring blocks automatic repetition instead of guessing. Provider throttling and outages are waited out within a bounded window; if the provider stays down, the run ends with its progress and a clear reason. Failure reasons are classified (billing, rate limit, context size, safety stop), with the provider's reference ID. Grok Bot shows each routine's recent success and failure history and keeps its 20 most recent run records. Its docs advise users to "Make retries idempotent where possible"; platform retry, or resuming from a failed step, is not specified in its public docs.
Sources:Grok Bot overviewSkills and routinesTeam BotsApprovals, security, and privacyGrok Bot securityTeams and enterprisesMessage and collaborateGrok Bot 101Introducing Grok BotTeam Bots announcementPlans and billingCursor pricing
Yes, and that's the split we'd suggest. Give each person a Bot for the work that needs a computer or a conversation: the portal with no clean API, the research, the drafts, the questions a Team Bot answers in Slack. Run what the company answers for through Boring: the queues, hand-offs, and recurring jobs that several people own, that start from other systems, and that need an assigned reviewer and a shared record. The two don't need to be connected to be useful side by side.
Partly, and it is a real step. A Team Bot is one Bot the whole team talks to, with shared plugins, skills, files, and team memory, an optional Slack app of its own, and each teammate's own account for plugins that need a sign-in. It is in public beta on Cursor Teams and Enterprise plans. Two things stay personal by design: each teammate's chat is private, and routines run as the person who set them up and report in that person's chat. Boring's agents belong to the workspace, so their triggers, approvals, and run history are shared, and the work doesn't depend on one person's chat.
For your own work, it often is. Approval cards, a model-based Auto Review, and Ask first rules give a member real control, and Enterprise admins can enforce Auto-review with locked team rules. The difference is who gets asked, what they can change, and what is left to a model. In Boring, the request goes to the reviewer you assign, can carry a due date and reminders, leads with the exact tool call, and can be approved, rejected, reassigned, or modified before it runs. An action an agent was never granted can't be called at all, and a numbered procedure runs in order, one step at a time.
SpaceXAI's security docs say "Cursor manages model selection. There is no customer-facing model picker", and its Enterprise model allowlist comes with the note that "enforcement is not guaranteed". On cost, Grok Bot usage is a weekly grant, then on-demand billing through Cursor when on-demand is on. SpaceXAI's docs say "A separate Grok Bot spend cap is not available today", and Cursor notes that the on-demand monthly limit "is not a hard stop in the middle of a run." Boring runs new agents on Claude Sonnet 5.5 by default, offers managed GPT, Gemini, and Grok with no key, and accepts your own Anthropic, OpenAI, Google, OpenRouter, or compatible-endpoint key; set a workspace default or pin a model per agent. Every run carries a per-run spend ceiling, and workspace daily and billing-period budgets with a pause switch are rolling out now.
No, and if the job lives on a website with no clean API, a Bot is the better tool. Boring agents act through 1,500+ connected tools, plus guarded first-party packs for selected APIs, and can load public web pages; they don't drive a desktop or sign in to sites. You work in the console, where the workspace assistant (⌘J) finds which agents need attention, what's waiting on a person, and where spend went, then prepares fixes, runs, or approvals as cards that change nothing until you confirm. Notifications go out by email and Slack, and a native mobile companion for approvals is built, with its store release pending.
We've tried to make it so. Every fact about Grok Bot comes from SpaceXAI's documentation, guides, and news posts, or from Cursor's Grok Bot plans and pricing pages, checked on 3 October 2026. We quoted SpaceXAI where the wording matters, and where its docs don't specify something we say exactly that rather than call it missing. The page also says plainly where Grok Bot wins: a computer of its own, conversation on desktop, phone, and in Slack, templates and a Marketplace, an Enterprise admin plane, and inclusion in plans many teams already pay for. Grok Bot is in beta and changing quickly; if we got something wrong, tell us and we'll fix it.
Request access and describe it in a sentence — or ask about white glove and our team will build and run it with you.