{"found":true,"collection":"patterns","library_url":"https://www.grokbotdb.com/library/pat.team-controls-day-one","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"pat.team-controls-day-one","name":"Set the team controls on day one","category":"safety","problem":"Team defaults are permissive: network policy allows all, template sharing is on, Action Recording is off.","technique":"On day one set the network policy, the MCP allowlist, Team Rules, Auto Review team instructions, public template sharing, and, on Enterprise, Action Recording with export to your own collector. Remember there is no team-level ceiling on local execution.","why_it_works":"Any permitted connector is available to every Bot every member runs, so policy is the only lever that scales.","when_to_use":"Before a team rollout.","manual_ref":"5.6","evidence":"documented","source_url":"https://docs.x.ai/grok-bot/teams-and-enterprises","related":["pat.local-execution-off","pat.strip-secrets-before-sharing","pat.connect-only-what-you-need"],"confidence":"high","first_seen":"2026-09-03","last_verified":"2026-09-03"}}