Official docs say not to use separate Bots as a security boundary. That’s correct, and it’s the gap.
Several Bots share one cloud computer and one Chrome. chrome://settings/content/all shows hosts and storage, not which account. A cookie-host list is not an inventory. Any Bot can use a session another Bot signed in (example: a site signed in as the human’s Workspace account).
What exists today: approval cards, Auto-review (Require / Always Allow), delete-the-bot. Persona text that says “read-only” is not a lock.
What’s needed:
A signed-in dashboard: Account | Site, grouped by identity. Not cookie hostnames.
Per-Bot browser profiles / credential isolation, or an explicit “this session is usable by Bot X only.”
Named standing writes with scope and revoke (Always Allow that is durable and auditable). Default everything else to a human confirm tap.
An action log: which Bot used which session, and which approvals fired.
Follow-up — the UX makes this worse than the docs say.
Grok Bot gives each Bot its own desktop / browser window on one shared cloud computer. Users see different windows and think sessions are isolated. They are not.
What is shared: files, installs, Chrome cookies. If Bot A signs into a site, Bot B opens that same site in its own window and is already in. No new auth. Bot B cannot see Bot A’s screen and cannot drag the window over. It does not need to. It gets the session, not the screen.
This is not multiple monitors on one Mac. On a real Mac you can see every display. Here the screens are separate and the login is not.
That is the gap item 2 is asking for: per-Bot browser profiles / credential isolation, or an explicit “this session is usable by Bot X only.” Until that ships, separate Bots are not a fence, and the UI currently teaches the opposite.
+1, this is hitting us in production. One of our Bots runs scheduling for a clinic, so it needs a Google session signed in at all times to check Google Calendar and keep appointments up to date. That session keeps getting signed out whenever another Bot signs in or out of Google on the same shared Chrome store, and calendar access drops without warning.
A correct fix would be to store cookies per Bot, so each Bot keeps its own independent session. With separate accounts in separate stores, Google wouldn’t see one session reused across several browsers. For example, one Bot holds my personal account and another holds the company account.
Technically, the launcher already seems to support this: the script that links each Bot’s Cookies and Login Data into the shared store takes the shared session directory as a setting. An opt-in “isolated session” toggle per Bot could point that Bot at its own session directory (for example one folder per Bot id) and leave the shared store as the default for everyone else. That keeps today’s “sign in once” behavior for most Bots and gives durable isolation where it’s needed.
Could someone from the team share whether this is on the roadmap? Please reply here, I’m following the thread.
Today all Bots on one account share a single browser session on the cloud computer, so a Google sign-in or sign-out in one Bot’s window affects the others. Letting an individual Bot keep its own separate browser session is something the team is actively working on!