GROK BOT / configure-grok-bot-network-controls

Grok Bot

Configure Grok Bot Network Controls (Enterprise)

Configure Grok Bot Network Controls (Enterprise)

Network Controls set which destinations team Grok Bot computers can reach. The panel is Enterprise only on the Grok Bot page of the Cursor dashboard. Self-serve Teams do not see it and cannot set a destination allowlist. Official guide: Grok Bot security → Network policy.

Teams without a policy default to allow-all.

Modes

Mode Effect
No policy Allow all (default when no policy is set)
Allow all network access Explicitly allow all destinations
Defaults plus team allowlist Cursor’s default destinations plus your list
Team allowlist only Only your list, plus destinations a computer needs to function

Destinations cover web domains and IP ranges with ports for raw connections. There is no documented cap on the number of entries.

Set or change the policy

  1. Sign in as an Enterprise admin and open Grok Bot in the Cursor dashboard.
  2. Open Network Controls.
  3. Pick a mode. For a locked-down rollout, use Team allowlist only or Defaults plus team allowlist.
  4. Add the domains and IP:port ranges members need for company tools.
  5. Save. The policy applies when a computer is created or recreated. Recreate or restart a running member computer so the new policy takes effect.

Directory groups and lock

Inside Network Controls (Enterprise):

  • Directory groups can set their own network policy, which replaces the team policy for their members.
  • A lock makes the team policy effective for everyone (group overrides stop applying).

How this differs from related controls

Control Relationship
Connector / MCP policy Separate layer. Blocking a plugin does not block that service’s website. Close both paths when you need both closed.
Cloud Agent network settings Separate from Grok Bot Network Controls. Changing one does not rewrite the other.
Static egress IPs Hosted computers use shared static egress ranges (not per-customer). Treat them as identifying Grok Bot traffic. Ask your Cursor account team for current ranges. The product control for destinations is this allowlist, not a source-IP editor.

If your company inspects TLS, allow Cursor’s published hostnames and bypass inspection for them — your account team can provide the current list.

Pitfalls

  • Self-serve Teams will not find Network Controls — that is expected for the plan, not a missing entitlement.
  • Saving a tighter policy does nothing for already-running computers until recreate/restart.
  • Restricting egress limits where data can be sent; dedicated DLP hooks are not available on this control.
  • Team Setup (Enterprise) can install a private networking client on every team computer — that path is separate from shared egress ranges.