{"found":true,"collection":"patterns","library_url":"https://www.grokbotdb.com/library/pat.bots-are-not-a-security-boundary","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"pat.bots-are-not-a-security-boundary","name":"Do not use separate Bots as a security boundary","category":"safety","problem":"The natural assumption, repeated in otherwise careful tutorials, is that each Bot has its own computer.","technique":"Assume every Bot on the account shares one machine: files, browser sessions, logins, command-line credentials, connectors and local-computer permission. Design as though any Bot can reach anything.","why_it_works":"Each user gets one Firecracker microVM; each Bot gets a screen on it, and screens are work surfaces rather than security boundaries.","when_to_use":"Every security decision about this product.","manual_ref":"1.2","evidence":"documented","source_url":"https://docs.x.ai/grok-bot/faq","related":["pat.separate-cursor-user-for-isolation","pat.scoped-service-accounts","pat.connect-only-what-you-need"],"confidence":"high","first_seen":"2026-09-03","last_verified":"2026-09-03"}}