DELXSECURITY

Architecture note / agent fleets

Shared-computer agent fleets: isolation, automated review and deletion are not the same control.

Always-on agent teammates that share one computer change the control plane. A separate Bot is not isolation. Model-based Auto Review is not a control. Deleting a Bot is not a wipe of sessions or files.

Direct answer

Three facts that do not collapse into one setting

When several named agents share one user-scoped cloud computer, they share files, browser sessions and application logins. Automated review of tool calls is model-based assistance, not least privilege. Deleting a named agent does not remove the shared workspace or signed-in sessions. Design isolation, approval and wipe as separate controls, then verify each in the live system.

What the vendor documentation already states

SpaceXAI published Grok Bot on 11 August 2026 as persistent named teammates that share one cloud computer, can sign into apps and websites, and can run routines while a laptop is closed. The public product and security pages are the source for the three mappings below. This note restates those properties as control questions. It does not add unpublished internals, exploit steps or a product score.

01

Shared computer ≠ isolation

Official overview: all Bots use the same persistent cloud computer assigned to the user account. Files, browser sessions and command-line credentials on that computer are available across the Bot roster. Each Bot may have its own screen; that is parallelism, not a separate security boundary. Do not use separate Bots as isolation.

02

Auto Review ≠ control

Official approvals page: Auto Review is model-based evaluation of tool calls and computer actions. Require-approval rules can stop a match; always-allow rules proceed only when review finds no other reason to stop. The same page says Auto Review should complement, not replace, least privilege and explicit approval. Broad browser allow-rules are unsafe because websites change.

03

Delete Bot ≠ wipe

Official approvals page: deleting a Bot does not remove shared-computer files or browser sessions. Ending access still requires signing out of websites, uninstalling connectors, revoking authorization in the source service and removing sensitive project files. Hide or delete is a roster action, not a wipe.

Evidence to verify

  • Written statement of whether the fleet shares one computer or isolated runtimes.
  • Inventory of shared files, browser sessions, connectors and local-computer execution.
  • Approval rules that name send, purchase, publish, delete, permission change and production writes.
  • A test that Auto Review is present or absent, and a record that it is not treated as the only gate.
  • A deletion drill: after the agent is removed, remaining sessions, files and connector grants are listed and revoked.

What this note is not

  • Not a certification, customer logo, market-size claim or product ranking.
  • Not an exploit demonstration or a how-to for abusing a shared computer.
  • Not a substitute for the vendor's current security documentation or for written Rules of Engagement on a live system.
  • Not a claim that Delx Protocol, Delx Commerce or Delx Security makes a shared-computer fleet safe.

Primary sources

Direct answers

Q&A

Is a separate named agent a security boundary?

Not on a shared computer. If several agents use the same user-scoped machine, files, browser sessions and application logins are available across the roster. Treat a login or file placed on that computer as available to every agent that can use it. Separate names, roles or chat threads do not isolate credentials.

Q&A

Does automated review replace human approval?

No. A model-based auto-review can complement explicit allow and deny rules, but it is not a substitute for least privilege, scoped credentials or an approval that names the target and effect. Broad rules such as allowing everything in a browser change as websites change.

Q&A

If I delete an agent, are its files and sessions gone?

Not necessarily. Deleting a named agent typically removes that teammate from the roster. Shared-computer files, browser sessions and connector authorizations can remain until they are signed out, revoked in the source service and removed from the shared workspace. Deleting the agent is not a wipe.

Q&A

Does this note certify any vendor product?

No. This is an architecture mapping of documented shared-computer, review and deletion properties. It is not a product review, certification, customer case study or guarantee that any control works in a particular deployment.

Q&A

Can Delx Security review a shared-computer agent fleet?

A bounded engagement may map isolation, approval, connector scope, deletion and wipe evidence for an authorized owner. Active testing starts only after written Rules of Engagement name assets, techniques, data handling, timing, contacts and stop conditions.