
Grok Bot
Toggle Cloud Agent delegation for Grok Bot
Toggle Cloud Agent delegation for Grok Bot
Team and Enterprise admins can allow or block Grok Bot from spawning Cursor Cloud Agents for coding work. The control is team-wide and lives on the Grok Bot page of the Cursor dashboard. Official guide: Grok Bot for teams and enterprises → Admin controls → Cloud Agents.
Default is on. Turn it off when Bots should stay on the hosted computer and must not launch separate cloud coding VMs.
Who can change it
Admins on Teams and Enterprise. Members never see the Grok Bot admin page. The toggle applies to the whole team — there is no per-Bot override in the docs.
Change the toggle
- Sign in as a team admin and open Grok Bot in the Cursor dashboard.
- Find Cloud Agents (delegation / spawning).
- Leave it on to allow Bots to launch Cloud Agents under your existing Cloud Agent controls.
- Turn it off to block spawning across the team.
Cloud Agent network settings are separate from Grok Bot Network Controls. Changing one does not rewrite the other.
When to leave it on
- Members routinely hand coding tasks to a Cloud Agent from a Bot chat.
- Your team already trusts Cloud Agent repo access and spend controls.
When to turn it off
- Security review wants Bot work confined to the Firecracker computer without extra VMs.
- Cloud Agent spend or repo blast radius should be gated at the product boundary, not per approval.
False “Legacy Privacy” blocks on Cloud Agents are a different issue: Fix Grok Bot Cloud Agent false Legacy Privacy.
Pitfalls
- The default is permissive — audit this on first rollout even if you never opened the page.
- Disabling Cloud Agents does not disable Grok Bot itself; only delegation is blocked.
- Enterprise Network Controls and this toggle are independent — tighten both if that is the intent.