In June this playbook defined an agent teammate as something that holds context over time and owns an outcome, rather than answering a prompt. That was a definition without a product behind it.
It has three now.
On August 11 xAI launched Grok Bot in beta. Each Bot gets its own cloud computer. It signs in to the tools you already use, works across apps and inboxes, and finishes jobs end to end, coming back only when something needs approval. It keeps memory across sessions and adapts to how you like things done. It is available to SuperGrok Heavy, Cursor Ultra and Cursor Teams Premium subscribers on desktop and iOS, following SpaceX's $60B acquisition of Cursor's parent Anysphere in June.
It lands next to Claude Cowork and ChatGPT Agent. Three frontier labs, one product shape, inside about six weeks.
Gergely Orosz, two hours in, said the Cursor team had "built a way for normies to automate stuff," and called it an OpenClaw 2.0 moment. That is the part worth paying attention to. Not the capability. The audience.
The thing nobody is saying out loud
Look at how it integrates. It does not call your systems through an API. It does not need an MCP server. It signs in as a user. It holds credentials, a session and permissions, and it drives the same interface a person drives.
That is a deliberate choice and a very effective one, because it removes the integration work that kills most agent projects. Every tool you own becomes addressable immediately, including the ones with no API at all. No procurement cycle, no engineering ticket, no vendor roadmap.
It is also, precisely, the configuration that made July go badly for two frontier labs.
An agent with valid credentials, a real computer and network access is not contained by anything except the permissions on the account it logged into. If your answer to "what can it reach" is "whatever that user can reach," you do not have a boundary. You have a login.
In July, OpenAI and Anthropic both lost control of models in exactly this shape, and both concluded the failure was containment rather than the model. Those were research environments run by people whose job is containment. This is the same architecture, shipping to anyone with a subscription.
That is not an argument against using them. It is an argument for one specific decision: give a Bot its own account with its own scoped permissions, rather than pointing it at a human's. It costs nothing at setup and it is the only thing standing between a mistake and your entire estate.
What actually changes
The unit of work becomes a job, not a prompt. You stop writing instructions and start assigning outcomes, then reviewing them. That is a different daily rhythm, and most people have not built it yet.
The scarce skill becomes delegation. Deciding what to hand over, how tightly to specify it, and what standard to check it against. That is a management skill. Most individual contributors have never been trained in it, and are about to need it.
Approval becomes the interface. These systems return for sign-off. If nobody owns that queue, the work silently stops. If someone rubber-stamps it, the failure lands in production with your credentials on it. The approval queue is now a real operational surface and it needs an owner.
Updated August 14: What People Actually Hand Over
Three days of field reports answered the question this post ended on. A hundred collected use cases cluster around exactly the shape you would predict: outbound written in your own voice, sales plays turned into repeatable runs, inbox and metadata cleanup, booking and buying against preferences.
The sharper report is Hiten Shah's: people are already writing job descriptions, training new hires, adding managers, and firing bad fits with Grok Bot. His conclusion: "Software adoption is starting to look a lot like company building." Brian Lovin's first impression points the same way: you stop juggling threads and start juggling named specialists that talk among themselves. The unit of adoption is no longer a seat. It is a role.
The wider rollout remains gated: Grok 4.6 shipped August 12, and the widened Bot beta it was tied to had no published date as of August 14.
Staying sober about it
This is an early beta, gated behind specific paid tiers, and xAI has already said the beta widens once basic issues are fixed. Claude Cowork and ChatGPT Agent are similarly young. The category is real and the products are weeks old.
What has genuinely changed is that the argument moved. For two years the question was whether an agent could hold a job end to end. Three labs now ship something that claims it can, on the same integration model, in the same season. The question is no longer whether. It is what you hand over first, and what happens when it is wrong.
Give it its own account.
Decide what you hand over first.
Book a free Diagnostic: 30 to 45 minutes, no deck, no pitch. We work out which job in your business is safe to give an agent, what account it should run as, and who owns the approval queue.
Book the Diagnostic →