
Grok Bot
Enable or disable Grok Bot on Enterprise
Enable or disable Grok Bot on Enterprise
The organization-wide Enable Grok Bot switch is Enterprise only. It lives on the Grok Bot page of the Cursor dashboard and is admin-only. Official guide: Grok Bot for teams and enterprises → Admin controls.
Self-serve Teams do not get this switch. Their dashboard shows Learn more and an onboarding path; members already have Bot access per the Teams plan row.
Before you enable
- Move off Privacy Mode (Legacy) in Team Settings — Legacy blocks Grok Bot entirely and you are prompted to change it before enabling.
- Plan for shared static egress IPs if company tools gate by source IP (ask your Cursor account team for current ranges).
- Decide how members sign in to company tools from the hosted computer (SSO / IdP device policy).
- Audit connector/MCP policy and review Cloud Agents + public template sharing defaults (both ship permissive unless you tighten them).
Turn it on
- Open Grok Bot in the Cursor dashboard (admins only).
- Incomplete setup shows Disabled and Enable. Enable opens a setup modal covering privacy mode, pricing, and model availability.
- After setup finishes, the page shows Enabled and Disable.
Members on a pooled Enterprise team whose admin has not finished setup see a team-setup message instead of a request path — finish Enable before they can use Bot.
Turn it off
Click Disable on the same page. Disabling blocks members and does not delete member computers. Disk and prior work remain; members simply cannot run Bot until you enable again.
Related Enterprise-only controls on the same page
| Control | What it does |
|---|---|
| Network Controls | Destination allowlist for team computers (default without a policy: allow-all) |
| Team Setup | Admin install scripts on every team computer |
| Action Recording | Off by default; events need OpenTelemetry Export to leave Cursor |
| Computer management | Organization admins only — look up / terminate any member computer |
Teams-and-Enterprise controls that are not Enterprise-gated: Cloud Agents toggle, public template sharing, Team Rules, Auto Review team instructions, connector marketplace policy.
Pitfalls
- Self-serve Teams will not find an Enable switch — that is expected, not a missing entitlement.
- Disabling blocks access without wiping computers; re-enable to restore, do not assume a fresh computer was created.
- Finish privacy-mode migration before Enable or the modal will stop you.