{"found":true,"collection":"facts","library_url":"https://www.grokbotdb.com/library/fact.security.session-survives-authentication","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"fact.security.session-survives-authentication","subject":"security","claim":"After a human authenticates a site, the browser session stays live on the shared computer and is reachable by every Bot, so the session and not the password is the thing to plan around.","kind":"risk","status":"current","tier":"third_party","source_id":"src.tp.gauraw.complete-guide","source_url":"https://www.gauraw.com/grok-bot-complete-guide-ai-agent-team/","quote":"After authentication, the browser session may remain active on the shared computer. Plan around the session, not merely around how the password was entered.","observed_at":"2026-09-03","confidence":"high","notes":"Developers Digest gives the countermeasure: sign out of unused services to restrict Bot reach.","first_seen":"2026-09-03","last_verified":"2026-09-03"}}