
Grok Bot
Set Execution on Local Computer for Grok Bot
Bots can run commands on the desktop in front of you, read local files, and move files between the cloud computer and that machine. That path is separate from work on the hosted computer and separate from Auto Review. Official guides: Settings and notifications and Grok Bot security → Local execution.
Per-command approval is the default. Prefer Never unless a Bot has a specific reason to touch local files.
Open the setting
- Open Grok Bot settings from the account menu or with Cmd+, (Ctrl+, on Windows/Linux).
- Under General → Agent, find Execution on Local Computer.
- Choose one policy for this desktop installation:
- Ask every time — each local command stops for an approval card that shows the exact command.
- Always allow — matching local commands can run without a fresh card (still subject to other gates).
- Never — Bots cannot run local commands on this desktop.
The setting applies to the desktop where you change it. Another installation needs its own choice.
When team policy caps the option
On Enterprise, an admin can cap Execution on Local Computer for the whole team from the Grok Bot page of the Cursor dashboard. Your own setting still applies when it is stricter than the team cap. If local work is blocked, check whether your admin turned the team control down to Never before you chase an app bug.
Keep local work distinct from the cloud computer
Local execution is for the machine in front of you. Cloud work, plugins, and computer-use sessions still run on the hosted computer. Auto Review governs risky actions inside the hosted computer; it is not the same control as Execution on Local Computer. Approvals for cloud work and approvals for local commands are separate cards.
Pitfalls
- Leaving Always allow on when you only needed one local copy or read — switch back to Ask every time or Never after the job.
- Assuming the cloud Bot can see your laptop files without local execution — it cannot; grant the policy only for the tasks that need it.
- Confusing Auto Review rules with the local-execution policy — fix the wrong panel and the card still appears (or never appears) for the other path.
- Expecting one desktop's choice to follow you to another machine — set the policy again on each install.