GROK BOT / enable-or-disable-grok-bot-on-enterprise

Grok Bot

Enable or disable Grok Bot on Enterprise

Enable or disable Grok Bot on Enterprise

The organization-wide Enable Grok Bot switch is Enterprise only. It lives on the Grok Bot page of the Cursor dashboard and is admin-only. Official guide: Grok Bot for teams and enterprises → Admin controls.

Self-serve Teams do not get this switch. Their dashboard shows Learn more and an onboarding path; members already have Bot access per the Teams plan row.

Before you enable

  1. Move off Privacy Mode (Legacy) in Team Settings — Legacy blocks Grok Bot entirely and you are prompted to change it before enabling.
  2. Plan for shared static egress IPs if company tools gate by source IP (ask your Cursor account team for current ranges).
  3. Decide how members sign in to company tools from the hosted computer (SSO / IdP device policy).
  4. Audit connector/MCP policy and review Cloud Agents + public template sharing defaults (both ship permissive unless you tighten them).

Turn it on

  1. Open Grok Bot in the Cursor dashboard (admins only).
  2. Incomplete setup shows Disabled and Enable. Enable opens a setup modal covering privacy mode, pricing, and model availability.
  3. After setup finishes, the page shows Enabled and Disable.

Members on a pooled Enterprise team whose admin has not finished setup see a team-setup message instead of a request path — finish Enable before they can use Bot.

Turn it off

Click Disable on the same page. Disabling blocks members and does not delete member computers. Disk and prior work remain; members simply cannot run Bot until you enable again.

Related Enterprise-only controls on the same page

Control What it does
Network Controls Destination allowlist for team computers (default without a policy: allow-all)
Team Setup Admin install scripts on every team computer
Action Recording Off by default; events need OpenTelemetry Export to leave Cursor
Computer management Organization admins only — look up / terminate any member computer

Teams-and-Enterprise controls that are not Enterprise-gated: Cloud Agents toggle, public template sharing, Team Rules, Auto Review team instructions, connector marketplace policy.

Pitfalls

  • Self-serve Teams will not find an Enable switch — that is expected, not a missing entitlement.
  • Disabling blocks access without wiping computers; re-enable to restore, do not assume a fresh computer was created.
  • Finish privacy-mode migration before Enable or the modal will stop you.