This is a Botski briefing of public official pages. It is not a new product announcement dated today.
Put the stop line in the first message
Approvals, security, and privacy starts with a boundary in the request. Tell the Bot which actions it can take and where it must stop.
Official examples prefer explicit stops for sending messages, publishing, purchases, deleting or overwriting data, changing permissions, production changes, and accepting legal terms.
A useful first message names both sides: what the Bot may do now, and what it must bring back for you. Get started calls that last piece a review point — when the Bot should stop for you.
An approval controls the proposed action. It does not undo work already finished. Write the stop line before the Bot starts clicking.
Passwords stay on the computer, not in chat
When the Bot reaches a login, Get started says it may ask you to take over the computer. Open Agent Computer from the conversation, take control, enter the password, passkey, two-factor code, or CAPTCHA yourself, then return control.
Use the computer and apps lists the same take-over steps: a password or passkey, two-factor authentication, a CAPTCHA, a payment or identity check, or a site that explicitly requires a human. Avoid pasting passwords or one-time codes into chat.
If a supported connection presents a secure secret request, enter the value there. Official docs say that value is masked and is not added to the conversation. That is still not a general-purpose password box in chat.
On September 16, 2026 the official Grok Bot account on X said Bots can use 1Password: share items in a vault, approve each fill, and keep the secrets in your password manager. That matches the docs: you approve the sensitive step. You do not paste the password into chat.
Review before you allow a send
When an action needs approval, the conversation shows the proposed operation and its inputs. Approvals, security, and privacy says to review the target, scope, and values before you allow it. Do not approve an action whose target or effect you cannot identify.
Start with drafts. Keep sending, purchasing, deletion, and production changes behind your yes.
Independent, not xAI
Botski is an independent project. These notes help beginners read official public pages. They are not official xAI documentation, and Botski is not endorsed by X, xAI, or Grok.
If you want a first job written down before you open the official app, use Plan your bot on Learn. Official approval rules stay at Approvals, security, and privacy.
