AI agents/Grok Bot guides/Tutorial 6

How Do You Keep Candidate Data Safe When You Use Grok Bot?
The settings and habits that keep a recruiting bot inside its lane: Ask first rules, secure sign ins, the shared computer boundary, local computer access and how to remove access when a project ends.
- 6 of 6tutorial
- 8 minread
The short answer
Write the stop rule into every bot, add Ask first rules for anything that sends, changes or deletes, and sign in to tools yourself through the computer takeover. Remember that all your bots share one computer, so a file or login one bot can reach, they all can.
Give each workflow the least access it needs and remove it when the project ends.
What should every bot’s description say?
xAI’s approvals, security and privacy page tells you to name the actions the bot may take and where it must stop. For a recruiting bot, name at least these:
- Sending messages or invitations
- Moving, rejecting or editing a candidate in the ATS
- Publishing a job post
- Deleting or overwriting files or records
- Changing permissions or accepting terms
Standing rules: You draft and prepare. You never send an email, LinkedIn message or calendar invitation, never change a candidate's stage or status, and never delete anything without my approval. Show me the target, the exact wording and the reason before you ask.
How do Ask first rules work?
With Auto Review on, Grok Bot evaluates tool calls and computer actions before they run. Add rules under Settings, General, Bot, Auto-review. Ask first rules always stop a matching action for you. Allow automatically rules let an action through only if the automated review sees no other reason to stop. If both match, Ask first wins. xAI’s examples include “Ask first before sending any external email”.
Good starting rules for a recruiter:
- Ask first before sending any external email or message.
- Ask first before creating a calendar event with a guest.
- Ask first before changing a record in the ATS or CRM.
- Ask first before deleting any file.
Avoid broad allow rules such as “allow everything in the browser”. xAI notes that Auto Review is model based, so treat it as an extra layer on top of least privilege, not a replacement. When a request appears, read the target and the values. On desktop you can choose Allow once or Deny. If you cannot tell what an action does, ask the bot to explain it or produce a draft first.
How should you handle logins?
Passwords, passkeys, two factor codes, CAPTCHAs and payment confirmations are for you, not the bot. Open Agent Computer, take control, complete the step and hand control back. Do not paste passwords or one time codes into the chat. For a supported connection, use the secure secret request, where the value is masked and kept out of the transcript.
What does the shared computer mean for candidate data?
Every bot on your account uses one cloud computer with shared files, browser sessions and command line logins. xAI’s guidance is not to use separate bots as a security boundary. For a recruiter, that means:
- A candidate spreadsheet saved by one bot can be read by every other bot on your account.
- A signed in ATS session is available to all your bots.
- Connectors are account wide, not per bot.
Keep client data separate by removing files and signing out when a project ends, not by relying on separate bots.
What about your own computer?
The cloud computer is separate from your Mac or Windows machine. A bot can run commands on your own computer only if that is enabled and you approve it. The default is Ask every time. Leave it on Never allow unless a bot has a specific reason to work with local files.
Is it allowed at your employer or client?
Sending candidate data to another computer is a decision for your employer or client, not only for you. Get approval, update your candidate notice if needed and read how your Cursor account handles data. xAI says Grok Bot requires cloud data storage and does not support Legacy Privacy Mode, and that training opt out follows your Cursor account and privacy settings. The hiring laws lesson covers what applies when a bot helps screen people.
How do you remove access when a project ends?
- Pause or delete the related routines.
- Sign out of the websites on the shared computer.
- Uninstall connectors and revoke them in the source service.
- Delete sensitive files from the shared workspace.
- Hide or delete the bot. Deleting a bot does not remove files or browser sessions on the shared computer.
Our 40 Grok Bot rules post lists more habits, and the Vet bot reviews a shared bot before you install it.
Quick answers
Does a share link give someone my files?
No. Sharing a bot copies its configuration only, not your computer or logins. Still, keep secrets, candidate data and internal URLs out of any bot you share.
Is one bot per client safe enough?
No, not on its own. Bots on one account share a computer. Use separate accounts or strict clean up if client data must stay apart, and check with the client.
Explore in the directory
Grok Bot tutorials for recruiters
- How do you use Grok Bot to source a candidate shortlist?
- How do you use Grok Bot to schedule interviews?
- How do you use Grok Bot for interview scorecards and debriefs?
- How do you use Grok Bot to find companies that are hiring?
- How do you turn a Grok Bot task into a weekly routine?
- How do you keep candidate data safe with Grok Bot?