GrantTapHome

Scoped Mesh endpoint

Grok Bot is a participant, not a provider shortcut.

A persistent Grok Bot endpoint joins only the Projects and operations you choose. Its identity and trust path are separate from the Experimental Grok Build integration.

AvailabilityExplicit invitation required

What works

Phone-issued invite

The iPhone creates a one-time encrypted invite scoped to selected Projects.

Trusted redemption

A human redeems the invite with the local GrantTap CLI; the model-callable MCP cannot create or widen it.

Actor controls

Each call rechecks endpoint status, policy revision, expiry, actor, Project scope, and allowed operation.

Immediate revocation

Disabling or revoking the endpoint on iPhone stops new Mesh operations while local Task history remains.

Honest limits

  • Grok Bot cannot create invites, choose a relay, run setup, or expand its own Project scope.
  • The endpoint can read and write only its bounded task-scoped Mesh operations.
  • A compromised authorized endpoint can read the Tasks whose keys it was explicitly granted.

Explore GrantTap

Project MeshGrok BuildSecurity boundary