Scoped Mesh endpoint
Grok Bot is a participant, not a provider shortcut.
A persistent Grok Bot endpoint joins only the Projects and operations you choose. Its identity and trust path are separate from the Experimental Grok Build integration.
AvailabilityExplicit invitation required
What works
Phone-issued invite
The iPhone creates a one-time encrypted invite scoped to selected Projects.
Trusted redemption
A human redeems the invite with the local GrantTap CLI; the model-callable MCP cannot create or widen it.
Actor controls
Each call rechecks endpoint status, policy revision, expiry, actor, Project scope, and allowed operation.
Immediate revocation
Disabling or revoking the endpoint on iPhone stops new Mesh operations while local Task history remains.
Honest limits
- Grok Bot cannot create invites, choose a relay, run setup, or expand its own Project scope.
- The endpoint can read and write only its bounded task-scoped Mesh operations.
- A compromised authorized endpoint can read the Tasks whose keys it was explicitly granted.