Grok Bot: per-Bot file/folder and database permission isolation on the same account

Feature request for product/service

Cursor Web

Describe the request

Problem

Today, all Grok Bots under one Cursor account share one cloud computer. Files, folder trees, browser logins, and connectors are available to every Bot. Official docs correctly say not to treat separate Bots as a security boundary.

I want to run several role Bots on one account (inbox, ops, research, sales, etc.) with hard least-privilege boundaries, not just persona text.

Request

Please add configurable per-Bot permission isolation for the same account, including at least:

  1. Documents / folders — grant Bot A access only to specific paths or project folders; other Bots cannot read/write them.
  2. Databases / data stores — grant Bot-scoped access to specific DBs, schemas, or tables (or connector scopes that enforce the same).
  3. Ideally extend the same model later to connectors and browser sessions; file/folder + database access is the priority.

This needs real enforcement (not prompt-only instructions).

Why it matters

Without this, the only real isolation is a separate Cursor account. Soft rules in a Bot persona are not enough for multi-Bot workflows that touch sensitive docs or production data.

Related

Thanks.