Grok Bot for RIAs
xAI's Grok Bot can sign into your apps and work around the clock. Here is where it helps an RIA, and what to check before it touches client work.
Grok Bot is a capable always-on assistant for a person's own work at an RIA: research, inbox and calendar, follow-ups, and one-off tasks the person checks. For repeated client work like account opening, CRM updates, and service requests, it plans each run fresh and keeps records per user, so most RIAs will want a verifiable agent for that work and keep Grok Bot for the rest.
This fall, three AI companies shipped the same idea within weeks: an agent with its own computer that works for you around the clock. xAI launched Grok Bot in August, Meta launched Muse in September, and OpenAI answered with dots at the end of the month. Operations teams at RIAs are already asking whether one of them can take work off their plate.
This guide is for that question. It covers what xAI's Grok Bot is, where it fits at an RIA, and the five things the firm has to answer before an always-on agent touches repeated client work. Every product fact comes from xAI and Cursor's own pages as of October 1, 2026, and these products are changing fast.
What is Grok Bot?
Grok Bot is xAI's always-on agent, launched in beta on August 11, 2026 and built and run with Cursor. Each user gets a persistent cloud computer with a browser, a filesystem, and a terminal. You create named Bots, give each one a job, connect them to apps like Gmail, Slack, and Notion, and they work on a schedule or when an event fires, coming back to you when they need approval.
Bots can message each other, hand work off, and run as a team, with a chief-of-staff Bot managing specialists. Since September, Grok Bot for Enterprise adds access, network, and audit controls, and Team Bots let a group share Bots.
Grok Bot is good at the work around a person: watching an inbox, prepping for meetings, researching a company, pulling numbers from a dashboard, and handing tasks between Bots without anyone writing code.
- Plans. Included with SuperGrok, Cursor Pro, and Cursor Teams. x.ai lists $20 a month (Cursor Pro), $30 (SuperGrok), and $40 per seat (Standard Teams), with Bot usage metered separately. Enterprise is through sales.
- Model. Cursor manages model selection. There is no customer-facing model picker.
- Saved work. "Teach a task" turns a recorded demonstration of up to 10 minutes into a draft skill, a reusable set of instructions. Routines run a skill on a schedule or after an event.
- Approvals. Allow once, Always allow, or Deny, plus Auto Review, a separate model that checks risky actions before they run.
- Records. Audit logs and Action Recording are Enterprise features. Action Recording is off by default and keeps 90 days.
- Certifications. ISO/IEC 27001 and ISO/IEC 42001 (Anysphere), with Grok Bot in scope.
Product details as of October 1, 2026, from the vendor's own announcement, help, and security pages.
Where RIAs want to use Grok Bot
Nobody at an RIA needs an agent to do the professional judgment. They want back the hours their teams spend on repeated, system-to-system work:
- Account opening. Turning a new household's details into completed custodian forms and sending them for signature in DocuSign.
- CRM updates. Getting meeting notes, tasks, and life events into Wealthbox, Redtail, Salesforce, or Practifi.
- Service requests. Handling address changes, distributions, and beneficiary updates from the shared inbox.
- Billing and reconciliation. Checking fee schedules and balances across Orion, Black Diamond, or Tamarac and the CRM.
- Review prep. Assembling the packet for each client review from the portfolio system and the CRM.
Picture a service associate teaching a Bot how to handle an address change: open the request in Outlook, update the household in Wealthbox, prepare the custodian's change form, and send it for signature. Grok Bot records the demonstration, drafts a skill, and a routine picks up each new request.
The edge cases are where an RIA lives: a joint account where only one owner moved, a trust with a different mailing address, a request that arrives with a distribution tucked into the same email. The Bot interprets its skill on each run, so those calls are made fresh by the model, and the firm's record of them is only as complete as its plan's logging. Self-serve Teams do not get the audit log.
Five questions before Grok Bot touches client work
None of these are reasons to avoid Grok Bot. They are the questions any RIA has to answer for any agent that acts on a client's behalf.
Will Grok Bot do the work the same way every time?
Grok Bot's skills are the closest any of the new always-on agents comes to a saved workflow, and they are a real step. But a skill is a set of instructions the model carries out on each run, not fixed steps. xAI's own docs say to re-test a skill after a website, plugin, or source format changes, and make no claim that two runs take the same path.
For account opening, CRM updates, and service requests, that matters. You cannot test a procedure on last month's cases and rely on the result if the next run is planned again from scratch.
Who supervises Grok Bot at an RIA?
Grok Bot acts as the signed-in member, so every action traces to a named person. That is the right foundation. Approvals are Allow once, Always allow, or Deny, and Auto Review checks risky actions first. The docs are candid that Auto Review does not cover every side effect, naming memory writes and most settings changes. Below Enterprise, each member sets their own rules.
Under the SEC's compliance rule, Rule 206(4)-7, an adviser needs written policies and procedures reasonably designed to prevent violations, and for dual registrants FINRA Regulatory Notice 24-09 reminds firms that Rule 3110 requires a reasonably designed supervisory system when they use generative AI. A procedure that is re-planned on every run is hard to write a policy around.
Can the firm show what Grok Bot did?
The firm-level record lives on Enterprise: audit logs of admin and control-plane events that can stream to a SIEM, and Action Recording of what Bots actually did, which is off by default and kept for 90 days. Self-serve Teams do not get the audit log.
SEC Rule 204-2 requires advisers to keep books and records, including copies of written communications on listed topics, generally for five years. An agent that emails clients or updates account records from a user's login is creating those records, and a per-user activity feed is not a books-and-records archive.
What happens to client data?
With Privacy Mode on, customer data is not used for training, and Cursor's zero-retention provider terms apply, though flagged data may be stored for investigation. Bot computers run in the United States, there is no per-organization retention policy yet, and all of one user's Bots share the same files and app logins.
Regulation S-P requires advisers to safeguard customer information and, since the 2024 amendments, to run an incident response program. An agent holding an adviser's email and CRM access is part of that program.
Cursor's security docs say its controls "reduce, but don't eliminate" risk from malicious content.
Does Grok Bot reach the systems RIAs run on?
Named plugins include Gmail, Slack, Notion, Salesforce, and GitHub. For everything else, Bots use computer use, clicking through web apps the way a person would.
RIA operations run through the CRM (Wealthbox, Redtail, Salesforce, Practifi), the portfolio system (Orion, Black Diamond, Tamarac, Addepar), DocuSign, and a stack of custodian forms. Reaching a system is only half of it; the other half is doing the same thing in it every time.
| Grok Bot | Caddi | |
|---|---|---|
| How the work is defined | A skill: instructions the model follows each run | Tested code you can read and change |
| Same input, same path? | Not claimed by the vendor | Yes, for the coded steps |
| Role of AI in a run | Plans and performs each step | Named judgment steps, scoped and logged |
| Human control | Allow once / Always allow / Deny, plus Auto Review | Review the procedure; exceptions go to a named person |
| Record of each run | Enterprise audit log; Action Recording off by default, 90 days | Every run logged, tied to its source documents |
| Built for | A person's own varied work | RIAs' repeated back-office workflows |
What a verifiable agent does differently
The fix is not a better prompt or a stricter approval setting. It is moving the procedure out of the model. A hybrid agent runs the workflow as code, which can be read, tested, and versioned, and calls AI only for the steps that need judgment, each one scoped and logged.
For account opening, that means the code pulls the household from the CRM, fills the custodian's forms, and sends the DocuSign envelope the same way every time, while AI handles the judgment inside it: reading a scanned trust document, matching a beneficiary to the right record, spotting a missing signature. Anything unclear goes to the operations team, logged.
That split is what makes an agent verifiable: a reviewer can read the procedure before it runs, every judgment call is on the record, and changes are made on purpose.
More on the idea in what are verifiable AI agents and what are hybrid agents.

Connect Wealthbox to Caddi
Allow1Sign in to your tools
One click each for Wealthbox, Docusign and Microsoft Outlook. No API keys.
Automate account opening.
ScreenshareType it2Show or tell it
Screenshare the job, or type it in chat. Change it any time.
- Running



14 done1 for review
3Watch it run
Caddi does the work and flags anything unsure for review.
How RIAs can use both
Grok Bot and a verifiable agent are not competing for the same job. Let people use Grok Bot for the work around them, where every task is different and the person who asked checks the result.
Put the repeated client work, account opening, CRM updates, and service requests, on an agent the firm can verify. That is what Caddi builds: an ops person shows Caddi the workflow on a screen share or describes it in chat, Caddi runs it as code across the firm's tools with the judgment steps logged, and the team changes it in plain English as the work changes. Across Caddi customers, 99% of agent runs complete successfully.
Keep reading
- What are verifiable AI agents?
- Grok Bot vs. Muse vs. Dots for professional services firms
- Grok Bot for law firms
- Grok Bot for professional services
- Meta Muse for RIAs
- OpenAI Dots for RIAs
- Caddi for RIAs and wealth managers
- Client onboarding automation
- RIA compliance automation
- Caddi + Wealthbox
- The Wealth Advisory COO's Guide to AI
- What are hybrid agents?
Caddi
See how Caddi AI Agents can run your RIA's back office the same way every time and log every run for compliance
Frequently asked questions
Is Grok Bot safe for RIAs?
Grok Bot has real safeguards: allow once / Always allow / Deny, plus Auto Review. For a person's own work, those are sensible. For repeated client work, an RIA also has to answer for supervision, records, and confidentiality, and Grok Bot plans each run fresh with records kept per user. Most firms will keep it for personal work and use a verifiable agent for client workflows.
Can Grok Bot run account opening, CRM updates, and service requests unattended?
It can attempt it: Grok Bot works in the background and can reach many apps. But it decides how to handle each case on that run, and the vendor does not claim repeatable runs, so the firm cannot test the procedure once and rely on it. For unattended client work, a verifiable agent that runs the steps as code is the safer fit.
Does Grok Bot keep an audit trail?
The firm-level record lives on Enterprise: audit logs of admin and control-plane events that can stream to a SIEM, and Action Recording of what Bots actually did, which is off by default and kept for 90 days. Self-serve Teams do not get the audit log. For RIAs, check whether that record can be exported, retained, and reviewed at the firm level before relying on it.
Does Grok Bot train on our data?
With Privacy Mode on, customer data is not used for training, and Cursor's zero-retention provider terms apply, though flagged data may be stored for investigation. Bot computers run in the United States, there is no per-organization retention policy yet, and all of one user's Bots share the same files and app logins.
What should an RIA use for repeated client work?
A verifiable agent: one whose procedure you can read, whose judgment steps are logged, and whose every run leaves a record. Caddi builds these for RIAs. Your team shows the workflow on a screen share or describes it in chat, and Caddi runs it as code across your tools, with exceptions routed to a named person.