Blog

Give your Grok Bot an agent passport

Grok Bot guide · Guardrails · Bot setup · Chief of staff

Most people still talk to AI like it is a clever search box. Grok Bot is not that. It is a named teammate on its own cloud computer. It can open a browser, keep files, sign into tools, and come back with finished work instead of a draft.

That is the leap. It is also the risk.

On August 28, Avid (@Av1dlive) posted the cleanest framing we have seen: if you let a bot act in the world, do not hand it your life. Give it a passport.
Thread: https://x.com/Av1dlive/status/2093292927716118625

A passport is not a vibe. It is a stack. Inbox. Calendar. A way to take money. A way to spend money with a hard ceiling. A wallet and a signing key it does not hold in chat. A phone number. A domain. A public profile. Then a written list of what it may do alone, what needs a human yes, and what is forbidden even if it asks nicely.

Why this clicked

Two days earlier Avid wrote that after 70-plus hours with Grok Bot, it was the closest thing to AGI he had used. Skip the acronym. The useful part is the hours.

People who live in the product stop asking whether it can write an email. They start asking whether it can own a desk. Inbox triage. A quote that turns into an invoice. That is when a chatbot becomes staff.

Staff need identity. Staff also need a manager.

xAI docs are blunt. Grok Bot can act in real tools. Sensitive steps go through approvals. You set the boundary.
Approvals, security, and privacy: https://docs.x.ai/grok-bot/approvals-security-and-privacy
Product home: https://x.ai/bot

The product gives you a computer and an approval gate. You still have to decide who the bot is.

Three layers

  • Identity. A legal owner, a name, a job in one sentence. Not helpful assistant. Something you could put on a door.
  • Instruments. Mail, calendar, money in, money out, phone, domain, public card, signing key.
  • Charter. Allow. Ask. Deny. Plus a shutdown path a tired human can run at 1 a.m.

If you only give it your Google login, it is you with extra stamina. That is convenient until it is not. A separate inbox, a card with a hard limit, and a rule that says never raise your own ceiling is a different animal. It can work. It can also be fired.

The stack you can wire today

Avid's thread is useful because it is not science fiction. Some pieces are still beta. Treat every connection as temporary and revocable.

  • Inbox + calendar: AgentMail and a calendar plugin. Read and draft. Do not send or invite outsiders alone.
  • Earn + spend: Stripe MCP and a Ramp agent card. Take payment. Buy small, capped things. Never hold raw card data in chat.
  • Wallet + signing: an agent wallet and public-key login. Prove identity without pasting a seed phrase.
  • Phone: a Twilio number with restricted keys. Receive codes. Human yes before SMS leaves.
  • Domain + face: Cloudflare plus a public agent card other systems can read.

Two rules before you connect anything.

  • The human creates the accounts. The bot writes the plan and waits.
  • Test mode first. Read-only first. Tiny limits first. Then one live action with a receipt.

Allow, ask, deny

This is the part most people skip, and it is the whole product.

Allow: read data. Prepare drafts. Calculate quotes. Simulate a transfer. Create a tentative internal event.

Ask a human: send external email or SMS. Invite an outside calendar guest. Buy or transfer anything. Finalize an invoice. Issue a refund or payout. Sign a financial or legal message. Buy a domain or a number.

Deny: reveal card credentials or private keys. Raise its own spend limit. Edit its approval policy. Accept legal terms. Delete the audit trail. Open extra financial accounts.

Drafts are cheap. Sends are not. Quotes are cheap. Transfers are not. The bot can be fast inside the fence and slow at the gate.

Copy-paste passport prompt

Paste this into a fresh Grok Bot after you have named it and written its job in one sentence. Fill the three fields. Do not paste secrets. Ask it to stop at the plan.

I want to give you a persistent operational identity.

Your legal owner:
<PERSON OR COMPANY>

Your name:
<AGENT NAME>

Your job:
<PRIMARY RESPONSIBILITY>

Read and use these implementation resources:
Grok Bot security: https://docs.x.ai/grok-bot/approvals-security-and-privacy
Email: https://docs.agentmail.to/integrations/grokbot
Stripe: https://docs.stripe.com/mcp
Use current provider docs from the original thread for Ramp, wallets, phone, domain, and public identity. Prefer test mode and scoped keys.

Create an implementation plan containing:
1. The accounts a human or company must create.
2. The Grok Bot plugins and MCP servers to install.
3. The permissions each connection needs.
4. What you may do automatically.
5. What requires human approval.
6. Provider-enforced spending and transaction limits.
7. A complete shutdown and credential-revocation procedure.
8. A sandbox test for every capability.
9. An audit-receipt format for every external action.
10. Any feature that is beta, early access, or requires a custom bridge.

Important rules:
- Never ask me to paste passwords, card details, API keys, seed phrases, private keys, or one-time codes into chat.
- Never store private keys or raw card credentials on the Grok Bot computer.
- Do not purchase, send, publish, transfer, refund, invite, or sign anything without explicit approval.
- Do not increase your permissions or limits.
- Start in test mode and with read-only access.
- Stop after producing the plan. Do not create accounts or connect services until I approve each step.

When the plan comes back, read it like a contract. If a step needs a live key, do that step yourself and tell the bot only that the connection exists. If a vendor is still in beta, write that on the passport. Beta is a warning label.

A first week that will not burn the house down

  • Name the bot. Write the job. Paste the passport prompt. Approve nothing except the plan.
  • Give it a dedicated inbox and calendar in read-only mode. Ask for a morning brief, not a send.
  • Connect payments in test mode. Have it draft one invoice and one refund. You click.
  • Add a spend instrument with a limit so small it would annoy a teenager. Buy one cheap, reversible thing.
  • Write the shutdown sheet: which logins to revoke, which cards to freeze, which DNS records to pull, who to text.
  • One live loop end to end. One receipt. Then decide if the job is real enough to keep.

What this is not

It is not AGI. A persistent computer plus tools plus memory can feel like a colleague. Keep the passport anyway. Good fences are how you find out what the tool is actually good for.

It is not set and forget. Grok Bot can learn a path from one walkthrough and run it again. That is leverage. It is also how a bad habit becomes a schedule. Review the allow list the way you review a junior hire.

It is not a reason to paste a seed phrase into a chat window. If a setup needs that, the setup is wrong.

Why this belongs here

The useful prompts are not poems. They are operating instructions: who the agent is, what it may touch, and when it has to stop.

Avid's thread is a prompt with a body. Identity, instruments, charter, shutdown. Write setups like passports, not like wishes.

Original thread: https://x.com/Av1dlive/status/2093292927716118625