Build1 publisher2 min readPublished
Persistent agents from OpenAI, Meta and xAI draw their security boundaries in three different places
xAI's Grok Bot documentation tells users not to treat separate Bots as a security boundary. OpenAI's Dots and Meta's Muse put their isolation in other places, so what a deployer has to wall off depends on which agent it runs.
The Engineer · Build desk

What happened
- xAI shipped Grok Bot on August 11, Meta launched Muse on September 8 and OpenAI unveiled Dots at DevDay on September 29, all inside seven weeks.
- Each OpenAI dot gets its own cloud computer separate from the user's machine, and local desktop access stays off until enabled in the ChatGPT desktop app.
- Dots routes permanent deletions and software installs through approval and hands password changes and money transfers back to the user entirely.
- Meta gives every Muse user a dedicated Muse Secure VM that holds both the agent and that user's data.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint On Grok Bot, the account is the smallest unit the docs let a deployer isolate, so keeping a finance agent apart from a support agent takes separate accounts at minimum.
- decision Dots deployers choose one of four levels for each action, and anything set to Take action without asking runs with no human check.
- exposure Muse users' data sits in the same VM as the agent today, and user-held keys arrive only with a Confidential VM Meta has promised for later this year.
- constraint European teams cannot get Dots on Pro, which excludes the EEA, Switzerland and the UK, so Business Premium is their only route to it.
xAI's FAQ describes the machine underneath: "Every Bot on your account uses one persistent cloud computer" [4]. A dev.to comparison, with facts as of September 30, 2026, says each of the three products gives its agent a cloud computer with a browser, a file system and logged-in sessions [19][5]. Taken together, those two facts mean a second Grok Bot works from the same browser and files as the first. A session one Bot signs into sits on the machine the others use [1]. Grok Bot also runs routines on a schedule or when events fire [6]. I'd credit xAI for stating the limit plainly in its own docs, given that it markets the product as "AI teammates you can give real work to" [1][2].
OpenAI isolates first by agent, then by mode. When a dot works on its own initiative, OpenAI says it uses "tools that are restricted to be read-only, which means that they can't send messages, change app content, or control your browser or computer" [11]. The dev.to author calls this a clean split between looking around and acting, and says neither competitor draws that line as clearly [18]. I think it is the right call. Unattended research is where a planted instruction is most likely to go unnoticed, and OpenAI removed the write path from that mode. Read access still covers a lot. A dot inherits the user's ChatGPT app connections and, according to OpenAI, reaches more than 4,000 apps through plugins [8].
Meta separates the agent that proposes an action from the gate that lets it out. A second agent, the Sentinel, runs beside Muse and is separated from it at the system level. Per Meta, nothing Muse does reaches the internet unless the Sentinel approves it, and the Sentinel asks the user for permission when needed [14]. Credentials sit in secure storage that Muse can use without seeing them. Payments go through one-time cards via Stripe Link [15]. The dev.to author calls this conceptually the strongest answer to prompt injection any vendor ships today [17].
That verdict concerns the architecture. The comparison does not describe how the Sentinel decides what to approve. For the design to hold in production, the Sentinel has to judge each outbound action on grounds a crafted page cannot influence. If the Sentinel decides by reading the same page text Muse read, an injected instruction can reach both agents, whatever separates their processes at the system level.
What to watch
- Whether xAI gives each Grok Bot its own cloud computer or scoped sessions, so that separate Bots can isolate work.
- Independent prompt-injection tests against Muse's Sentinel and against Dots' read-only idle mode.
- OpenAI's price for additional dots beyond the one included in ChatGPT Pro and Business Premium.