Swa vs Grok Bot: A Serious AI Agent You Don’t Get to Point at the Right Model
If your team is looking at Grok Bot, the AI agent xAI has been talking up all year, here’s something worth settling before you hand it real work: you don’t get to choose which model does that work.
Despite the name, Grok Bot doesn’t promise you’re talking to Grok. There’s no model picker, the serving mix can change without notice, and the one admin control that exists ships with a warning that it may not be enforced. We’ll get to the exact wording, because the documentation is unusually blunt about it.
That’s one of several things worth understanding before you commit. xAI has shipped three separate products this year that all carry the Grok name and all claim to bring AI into how your team works. They don’t share a bill, a setup flow, or a memory. Understanding which one does what, and what any of them actually costs, takes more digging than it should.
We did that digging. Here’s what we found, and where each product genuinely holds up.
What Grok Bot actually is
Setting the fragmentation aside for a moment, Grok Bot itself is a serious piece of engineering.
Each Bot runs on a persistent cloud computer with its own browser, filesystem, and terminal. You create a Bot, give it a job and a name, and message it the way you’d hand work to a coworker. The Bot works through multi-step tasks across apps and websites, including sites without clean APIs, using a real browser the same way a person would. Work keeps running after you close your laptop, and when a Bot needs a decision only you can make, it comes back and asks.
Multiple Bots can run in parallel on the same account, coordinating with each other, sharing context, and handing off work without you acting as the router between them. Show a Bot a workflow once, and it can save it as a routine and run it again on a schedule.
The security architecture holds up to scrutiny too. Anysphere, the company behind Cursor, holds ISO/IEC 27001 and ISO/IEC 42001 certification, issued by Schellman, and Grok Bot is included in the current ISO scope. There’s a SOC 2 Type II attestation alongside them. Enterprise customers get real audit logs, network egress controls with a destination allowlist, SAML SSO through Okta or Entra, and a layered approval system where risky actions pause for a human decision before they run. Early customers include Legora, Supermicro, and ServiceTitan.
None of that is beta-quality hand-waving. It’s a genuinely different shape for an AI agent, and it’s worth taking seriously.
Where Grok Bot gets complicated
Here’s where it gets harder to recommend for most teams.
Two doors into the same product, and they don’t meet in the middle
There is no standalone Grok Bot SKU. You get it one of two ways. Through Cursor, at $20/month for Cursor Pro or $40 per seat for a Cursor Teams plan. Or through xAI directly, at $30/month for SuperGrok, with SuperGrok Plus, SuperGrok Heavy and X Premium+ also carrying access. Cursor describes the xAI route as a usage grant rather than a Cursor plan, so paying xAI leaves you owing Cursor nothing.
Two doors into the same product, priced differently, sold by two companies, and neither company’s page tells you which one you’re supposed to walk through. For an engineering team already inside Cursor, the bundling is free upside. For a sales, marketing, ops, or legal team, it’s a procurement question with no obvious answer.
Three products, three relationships, no shared memory
Grok Bot isn’t xAI’s only play here, and it isn’t even the first. In December 2025, xAI shipped Grok Business and Grok Enterprise, a straightforward per-seat chat assistant priced at $30 per user per month for Business, with Enterprise pricing available after a sales call. Separately, there’s Grok for Slack, a channel and DM bot you install into your workspace and then connect to your own xAI API key from console.x.ai, billed for usage on that key rather than bundled into any plan.
Three products, and here is the part that makes it strange: they are all the same company. SpaceX acquired xAI in February 2026, rebranded it SpaceXAI in July, and closed its $60 billion acquisition of Anysphere, the company behind Cursor, on August 14. Cursor, Grok, and X now sit under one corporate roof. Yet none of these products share memory, identity, or a bill. A Bot you build inside Grok Bot has no idea what your team asked the Slack app yesterday, and neither product knows what the other costs you.
It doesn’t live inside Slack, it visits
This is worth being precise about, because it’s easy to get wrong in either direction. Grok Bot is not absent from Slack. A Bot can search Slack and act on what it finds there as part of a task, the same way it can read Gmail or pull a file from Google Drive.
What Grok Bot doesn’t do is live inside Slack as a presence your team can mention in a channel. You reach it through a separate desktop app (macOS, Windows, or Linux) or the iOS companion app, sign in with whichever plan carries your access, and message a named Bot directly. Slack is a place the Bot can go, not a place it lives. If your team’s instinct is to type @something in the channel where the work is already happening, that instinct doesn’t work here.
You don’t choose the model, and neither does xAI, exactly
Despite the name, Grok Bot doesn’t guarantee you’re talking to Grok. Cursor’s own security documentation states it plainly: model selection is Cursor’s call, there’s no customer-facing model picker, and “the serving mix can change over time with no fixed vendor set guaranteed.” An enterprise model allowlist exists, but Cursor’s own onboarding flags that enforcement isn’t guaranteed either.
In practice, that means you don’t get to route a writing task to one model and a code review to another. You can see which model served a request afterward, since usage analytics record it and billing follows it. What you cannot do is decide in advance.
All your Bots share one computer
xAI’s enterprise page says each Bot “runs on its own computer in the cloud.” The documentation says something narrower, under a heading that reads “One computer, shared by all your Bots.” Every Bot on your account uses the same machine, where “browser cookies and signed-in sessions are shared,” “files are visible to every Bot,” and “command-line credentials are shared.” Each Bot gets its own screen, but the docs are explicit that these “are separate work surfaces, not separate security boundaries.”
In practice that means signing one Bot into Salesforce hands that session to every other Bot on the account. The isolation boundary is the person, not the job.
There’s a related gap in the audit trail. Action Recording, the log of what a Bot actually did, is off by default, and those events don’t appear in the dashboard’s Audit Logs at all. Getting them anywhere useful means configuring OpenTelemetry export to your own collector. Audit logs are Enterprise-only to begin with, so self-serve Teams customers don’t get that record at all.
Memory you can’t inspect, and no way to bring it with you
A Bot’s memory, files, and browser sessions persist across sessions on its cloud computer, which is part of what makes it feel like a real teammate over time. As of September 2026, the documentation describes no self-serve way to inspect what a Bot remembers, correct something it got wrong, or export that memory if you want to move it elsewhere. Deletion happens through a formal data processing agreement after your account ends, not a button you click. And the documentation is explicit that self-hosting is not supported today. The computer is Cursor-managed, full stop.
Where Swa is built differently
We built Swa around a different bet: one AI identity, everywhere your team already works, routed to whichever model actually fits the task, with memory you can see.
One product, every surface, no separate subscription required
Swa runs natively on Slack, Microsoft Teams, WhatsApp, SMS, and the web from a single @swa mention, all on one account, all sharing the same memory. There’s no separate app to install for Slack presence, no second subscription to buy first, no linked-account workaround. If your team lives in Slack, @swa is already there. If they move to WhatsApp on their phone, the same context follows them.
This is the difference that isn’t a feature gap. A model picker is something any vendor can ship in a quarter. Being present as an identity inside the tools your team already has open is an architectural decision made at the start. Grok Bot is a desktop application you open, so Slack is somewhere a Bot can be sent, not somewhere it lives. That is not an oversight on their part, it is the shape of the product.
Every model, including Grok itself, from one interface
Swa routes across 20+ models, including ChatGPT, Claude, Gemini, Perplexity, Grok, Deepseek, and Llama. Grok is one of the models your team can route a task to directly. Our intelligent routing picks the best model for the job automatically, or your team can specify one by name. Nobody is stuck wondering which model actually answered, because you choose, and you can see it.
Real browser automation and deep async research, not bolted on
Grok Bot’s browser-driven task execution is a real strength, and we built the same category of capability into Swa. Swa can drive a browser to complete tasks on sites that don’t have clean APIs, alongside its native integrations, the same way a person would, and it can run deep, multi-step research jobs that take longer than a single reply, working in the background and returning a full report when it’s done rather than making you wait on a spinner. Ask for a “deep dive” or a “full report” and Swa escalates automatically to the tier built for that.
Credentials Swa never holds
The flip side of any agent that signs into your tools is where those credentials end up. Swa’s answer is that it doesn’t hold them. Identity is delegated to Auth0, and Swa never sees or stores your credentials or payment information. Data handling is zero-retention, and every query and action is written to an audit trail your admins can read and export, on every plan rather than as an enterprise upgrade. When the question in a security review is “what did the AI do, and with whose access,” that is a question you can answer the same afternoon it is asked.
Agents that work on autopilot, already shipping
Swa agents can run on a schedule without anyone asking. A Friday report that monitors your Slack channels and Jira tickets and emails a summary to your manager. A daily sales pipeline snapshot pulled from your CRM and posted to #sales every evening. A morning digest that scans overnight Slack activity and DMs each team lead their action items before standup. This is live today, not a roadmap item, and it runs on the same account your team already uses to talk to Swa directly.
Your memory, inspectable and portable
What Swa has learned, the documents it’s referenced, the custom agents your team has built, and the full audit log of who asked what all live in your workspace, exportable to CSV in a click. No data processing agreement required to find out what your AI knows about your company.
No per-user fees, ever
Swa runs on flat-rate, token-based pricing shared across your whole team. Adding a user doesn’t add a line item. Teams regularly save up to 90% compared to stacking multiple per-seat AI products, which is exactly the trap a three-product, per-editor-license setup like xAI’s risks recreating.
Side-by-side: how the two compare
| Capability | Grok Bot (via Cursor) | Swa |
|---|---|---|
| How you buy it | No standalone product: buy through Cursor, or through xAI | Standalone, no other product required |
| Entry price | $20/mo Cursor Pro, $40/user/mo Cursor Teams, or $30/mo SuperGrok | Token-based, flat-rate, no per-user fee |
| Models used | Cursor-managed, no customer picker, no fixed vendor guaranteed | Your choice: ChatGPT, Claude, Gemini, Perplexity, Grok, Deepseek, Llama, 20+ total |
| Slack presence | Reachable by the Bot as a tool, not a channel presence | Native @swa mention in any channel |
| Microsoft Teams / WhatsApp / SMS | Teams via connector; no WhatsApp/SMS | Native across all four |
| Browser automation on non-API sites | Yes, a genuine strength | Yes |
| Deep, long-running research | Not the product’s focus | Yes, tiered fast/deep with automatic escalation |
| Scheduled, autonomous agents | Routines saved from demonstration | Live today, prebuilt templates included |
| Self-hosting | Not available | N/A, cloud-managed with zero-retention |
| Memory inspection/export | Not available self-serve | Exportable audit log, per user |
| Security certifications | ISO/IEC 27001, ISO/IEC 42001, SOC 2 Type II (Enterprise features gated by tier) | Aligned with SOC 2, GDPR, CCPA, NIST CSF and NIST 800-53 |
| Audit trail and data handling | Zero retention via provider agreements; audit logs Enterprise-only, Action Recording Enterprise-only and off by default; deletion via DPA | Zero-retention handling; every query and action logged, readable and exportable, on every plan |
Grok Bot’s cloud-computer architecture and its security engineering are real strengths, especially for engineering teams already inside Cursor. Swa’s advantage is not having to assemble that experience out of three separate products, two purchase paths, and three sets of memory that never meet.
Three questions worth asking before you commit
1. Which door is your team supposed to walk through?
Grok Bot arrives either through Cursor or through xAI, at different prices, through two separate checkouts inside the same parent company. If you’re an engineering team already inside Cursor, that question answers itself and the bundling is free upside. If you’re not, somebody has to make a procurement decision that neither vendor’s page makes for you.
2. How many separate AI relationships is your company actually managing?
Grok Bot through Cursor, Grok for Slack with its own API key, Grok Business or Enterprise for anyone who just wants a chat assistant. Three logins, three bills, and no shared context between any of them.
3. If your security team asks what the AI remembers about your company, can you answer today?
If the honest answer requires a formal request through a data processing agreement, that’s a real gap for regulated industries and a real annoyance for everyone else.
What teams are doing with Swa
- Sales teams use Swa for CRM updates from WhatsApp, competitive research via SMS, and proposal drafting in Slack, all from the same AI with the same memory.
- Engineering teams rely on Swa for code reviews with Claude, incident response with the fastest model available that hour, and documentation generated wherever the team already works.
- Marketing teams use Swa for content creation, deep competitive research, and campaign analysis, routed to whichever model handles each job best.
- Support teams handle ticket resolution and sentiment analysis across Slack, Teams, and SMS without switching tools.
- Legal and compliance teams run contract review and risk assessment with a full audit log that exports in one click.
- Operations and IT teams consolidate AI spend into one bill instead of reconciling three, and set up autopilot agents to catch what used to fall through the cracks.
When Grok Bot is the right call
There are real situations where Grok Bot earns serious consideration:
- Your team already pays for Cursor Pro, Pro+, Ultra, or Teams, so the cost is already absorbed.
- Your heaviest AI workload is long-running, browser-driven automation on sites without clean APIs.
- You’re comfortable not knowing exactly which model is doing the work on any given task.
- You don’t need Slack, WhatsApp, or SMS presence, only a desktop and mobile app.
- Memory transparency and self-hosting aren’t requirements for your team.
If most of those are true for you, Grok Bot is worth trying.
When Swa is the right call
For most companies we talk to, the answer points the other way:
- You want one AI identity across Slack, Teams, WhatsApp, SMS, and the web without buying a separate product for each.
- You want to choose the model for each task, including Grok itself when it’s the right fit.
- You need real browser automation and deep research without assembling three separate subscriptions to get there.
- You want scheduled, autonomous agents that are already live, not a routine you have to teach from scratch.
- You want to inspect, correct, or export what your AI has learned, on demand.
Most teams we’ve worked with need more than one of those. That’s why we built Swa the way we did.
What’s next
We looked at the same question when Anthropic shipped Claude Tag, and you can read that comparison and the rest of our writing on the news page. Grok Bot proves something real: a persistent cloud computer that keeps working after you’ve logged off, with a genuinely capable browser-automation layer underneath it, is a legitimate shape for an AI agent. The engineering behind it is serious, and the security posture backs that up.
What it hasn’t solved is coherence. Three products carrying the same name, sold through two different checkouts, none of them sharing memory or a bill, isn’t a platform. And they are not separate bets by separate companies that happen to share a brand. They are all owned by SpaceX. One company acquired every piece of this and still hasn’t made the pieces talk to each other.
The bet we made with Swa is the opposite one: one identity, every surface your team already works on, every model routed to the task it’s best at, including Grok when Grok is the right call, and a memory you can see and export whenever you need to.
Swa sets up in three minutes across Slack, Teams, WhatsApp, SMS, and the web. No credit card required, and no second subscription to reconcile. Or if you’d like a walkthrough of how the routing and deep research work in practice, our team is happy to talk.
One AI. Every surface. No second subscription required.