CONNECTORS / provision-connectors-as-team-admin

Connectors

Provision Grok connectors as a Business or Enterprise team admin

Provision Grok connectors as a Business or Enterprise team admin

On Grok Business and Enterprise, a team admin must add a connector in the cloud console before members can connect it. That gate keeps the org in control of which external services Grok can reach. Consumer self-serve users skip this step and connect directly on grok.com/connectors.

Official guide: Connector Management.

Open the team connectors page

  1. Sign in at console.x.ai.
  2. Select your team.
  3. Go to Grok Business → Connectors (or the Enterprise equivalent label).

Adding and removing connectors needs Team Read-Write permissions (typical for team admins). Without that role, ask an admin to provision for you.

Add a catalog connector

  1. Click + Add Connector.
  2. Select the service to enable for the team.
  3. Finish any required setup (for example admin consent for Microsoft services, or Salesforce OAuth Client ID / Client Secret per that connector’s guide).

The connector then appears in the team’s available list. Members open grok.com/connectors, choose New Connector, and complete their own OAuth.

Add a custom MCP server

  1. Click + Add Connector.
  2. Choose Other and enter the MCP server URL.
  3. Complete authentication the console asks for.

The server must be reachable on the public internet. Localhost and private IPs are rejected — use a tunnel (Custom MCP Tunneling) while the process stays running.

Manage after provisioning

From the same connectors page:

  • Configure — adjust access controls, allowed sites, or service-specific options.
  • Remove — delete the connector from the team. Members lose connect/use access; indexed data for that connector may be removed.

Service-specific admin steps live in each connector guide (SharePoint, OneDrive, Salesforce, and others linked from Connector Management).

What members still do

Admin provisioning makes the connector available to the org. Each member still signs in with their own account on grok.com/connectors. Grok queries under that member’s permissions. Disconnect is also per member on the connectors page unless the admin removes the whole team connector.

Pitfalls

  • Members who see an empty New Connector list on Business/Enterprise usually need admin provisioning first — not a broken password.
  • Team Read-Write is required to add or remove; read-only teammates cannot finish console setup.
  • For white-glove Enterprise connector help, contact xAI sales per the Connector Management note — not a substitute for console provisioning.