Grok Bot templates: verified facts
Dated, sourced facts on Grok Bot templates: what a copy carries, one computer per account, 50 routines per bot, 20 runs kept, group chats of 2 to 6.
A Grok Bot template is a shareable copy of a bot’s configuration, and the facts below are what xAI’s documentation and the Operator Pack’s own build say about it. Each fact is one to three sentences, carries its source, and shows the date it was checked. Nothing here is guessed. Where a number comes from a Botemplate observation rather than an xAI document, it says so.
What does a template carry?
-
Template sharing went live on 28 August 2026. The Grok Bot account posted “You can now share templates of your Bots with others.” Source: x.com/bot. Verified 30 August 2026.
-
A copied bot carries the profile, settings, enabled skills, routines and avatar. The docs describe a duplicate as carrying exactly that set. Source: Create and manage Bots. Verified 30 August 2026.
-
A copied bot does not carry conversation history, learned memory or chat attachments. The docs say a duplicate “does not copy conversation history, learned memory, or chat attachments,” and a shared bot is a copy. Any write-up that says a template carries selected memories contradicts this. Source: Create and manage Bots. Verified 30 August 2026.
-
The share link is public, and it exposes identity, description, skills and routines. “Anyone who has it can view the Bot’s shared configuration, including its identity, description, skills, and routines.” Source: Create and manage Bots. Verified 30 August 2026.
-
A shared bot does not share your computer or logins. “A public share link lets others copy the Bot’s configuration. It does not share your computer or logins.” Source: Approvals, security and privacy. Verified 30 August 2026.
-
Sharing is three steps. Copy the share link; send it; the recipient previews on x.ai, chooses Add to Grok Bot, and needs the Grok Bot app to finish. The docs do not say whether a link can be revoked or expires. Source: Create and manage Bots. Verified 30 August 2026.
-
Strip secrets before sharing. “Remove API keys, internal URLs, customer data, and anything else you would not put in a public document before you share.” Source: Create and manage Bots. Verified 30 August 2026.
Where does a bot run?
-
One computer per user account, not per bot. “The computer is assigned to your user account, not an individual Bot.” A member of a team is a user account, so in a team every bot a member owns runs on that member’s computer, and a bot copied to another account runs on that account’s computer. Source: Computer and apps. Verified 30 August 2026.
-
Bots on one account share files, browser sessions and command-line credentials. “Browser cookies and signed-in sessions are shared.” “Files are visible to every Bot.” “Command-line credentials are shared.” Source: Computer and apps. Verified 30 August 2026.
-
Separate bots are not a security boundary. “Do not use separate Bots as a security boundary.” Parallel bots get separate screens, but “the screens are separate work surfaces, not separate security boundaries.” Sources: Approvals, security and privacy, Computer and apps. Verified 30 August 2026.
-
Installed connectors are account-wide. “Their availability is not isolated to one Bot.” Source: Computer and apps. Verified 30 August 2026.
-
The shared workspace is
/workspace, and Reset restores the most recent durable snapshot. Settings offers Update, Recover and Reset; a template should treat the workspace as recomputable cache, never as the record. Source: Computer and apps. Verified 30 August 2026. -
Deleting a bot may leave its files and logins on the computer. Deletion removes the profile, conversation and routines; “files and logins on that computer may remain.” Sources: FAQ, Create and manage Bots. Verified 30 August 2026.
What are the limits?
-
50 bots and group chats combined per account. Source: Create and manage Bots. Verified 30 August 2026.
-
A group chat holds two to six bots. “In New chat, select two to six Bots.” Bot-to-group handoff messages are text-only. Source: Message and collaborate. Verified 30 August 2026.
-
A bot can own up to 50 routines. Source: Skills, routines and automations. Verified 30 August 2026.
-
The app keeps the 20 most recent run records per routine. A daily routine’s history rolls over in under three weeks, so anything worth keeping must be written to a system of record on every run. Source: Skills, routines and automations. Verified 30 August 2026.
-
Recording a task for a bot is limited to ten minutes. Source: FAQ. Verified 30 August 2026.
-
No published instruction-block limit; 6,219 characters observed working. xAI publishes no ceiling. Botemplate’s release gate holds every paste block under 6,219 characters after placeholder substitution, which is one observation of a block that was stored and read back whole, not a documented maximum. Source: Operator Pack release gate, a Botemplate observation. Verified 30 August 2026.
How do skills and routines work?
-
A skill has six recommended sections. When to use it; inputs and access; the order of work; how to validate the result; what to return; what requires approval. Skills are reached by typing
/in the desktop composer and are available across your bots. Source: Skills, routines and automations. Verified 30 August 2026. -
A routine has six fields. The owning bot; the schedule and time zone; the input source; the expected result; the approval boundary; what happens when a source is missing. One schedule, one time zone. Source: Skills, routines and automations. Verified 30 August 2026.
-
Slack messages and GitHub notifications are the only event triggers the docs name. Routines run on a schedule “or, where supported, after an event,” and the docs advise “a narrow matching rule and a clear response” over broad listeners. Source: Skills, routines and automations. Verified 30 August 2026.
-
Every automation should carry a no-data and stale-data policy. The docs ask for one. Source: Skills, routines and automations. Verified 30 August 2026.
-
There is no first-party Google Calendar plugin, and no first-party plugin for Meta, Google, TikTok or Amazon Ads. Bellwether reads meeting signals from CRM meeting objects and Gmail invitation metadata for the first reason; Waterline takes ad spend as an operator-maintained CSV for the second. Source: Operator Pack setup documents, a Botemplate observation against the connector list. Verified 30 August 2026.
How do approvals work?
-
Require Approval beats Always Allow. “If both kinds of rule match, Require Approval wins.” Require Approval rules always stop; Always Allow rules proceed only when automated review finds no other reason to stop. Source: Approvals, security and privacy. Verified 30 August 2026.
-
Rules should be narrow. “Write narrow rules around a known action and scope”; the docs’ example of what not to write is “allow everything in the browser.” Source: Approvals, security and privacy. Verified 30 August 2026.
-
Passwords, passkeys, two-factor codes, CAPTCHAs and payment confirmations stay with the human. “The Bot should hand you control of the computer.” Source: Approvals, security and privacy. Verified 30 August 2026.
Who can use it?
-
Eligible plans: SuperGrok Plus, SuperGrok Heavy, Cursor Pro+, Cursor Ultra, and Cursor Teams Standard or Premium. Source: Get started. Verified 30 August 2026.
-
Desktop on macOS and Windows, companion app on iOS, no Linux desktop app. “Grok Bot is not currently available as a Linux desktop app.” Sources: Get started, FAQ. Verified 30 August 2026.
-
Grok Bot requires cloud data storage. Legacy Privacy Mode is not supported. Sources: Get started, FAQ. Verified 30 August 2026.
What does this mean for a template you buy?
A Grok Bot template is exactly the text inside it, and the facts above say why. Facts 2, 3 and 5 together mean a copy arrives with no memory, no logins and no hidden state: the profile, settings, skills and routines transfer, and nothing else does. Facts 8 to 11 mean a bot’s permissions belong to the account rather than the bot, so a template has to carry its setup order in a document the buyer follows on their own computer. Facts 16 and 17 mean a routine that matters has to write its result to a system of record on every run, because the app keeps only 20 run records and a daily routine’s history is gone in under three weeks. Fact 23 means every routine needs a no-data and stale-data policy written in advance. And facts 25 and 26 mean a template can write narrow allow rules and let broad deny rules stand, because Require Approval wins whenever both match.
Every Botemplate bot is built against this list. Ledger is the worked example: read-only on Stripe and QuickBooks, seven routines with a missing-data protocol each, and no contact with a customer about an invoice it has not reconciled. How it works covers what arrives after payment, and the Operator Pack is all five for $69.
If a fact above is wrong or out of date, write to the address in the footer with the fact number and the source, and the page will be corrected with the date.