Overview
Grok Bot computers are Linux VMs with a browser and a terminal. Install the Formal Endpoint on every team computer with Enterprise Team Setup. Transparent Mode then evaluates the VM traffic against Formal policy. This guide blockshttps://mail.google.com and https://gmail.com. Gmail
serves the inbox on both hostnames. A rule that matches only one is bypassed.
Prerequisites
- A Cursor Enterprise team with Grok Bot Team Setup
- Outbound HTTPS to
api.joinformal.com
Create an API key
Use one machine-user API key for the Grok Bot fleet.1
Create the key
Go to API Keys and click Create API
Key. Assign it to a machine user.
2
Store it as a Team Secret
Open Grok Bot in the Cursor dashboard. Add a Team Secret named
FORMAL_API_KEY. Paste the Formal key. Team Setup injects Team Secrets
as environment variables. Do not put the key in the setup script.Install the Endpoint with Team Setup
1
Create a manifest
Go to Grok Bot → Team Setup. Create a manifest, for example
formal-endpoint. Add one entry with ID install-formal-endpoint.2
Copy the package link
In the Control Plane, click Download Formal
Endpoint at the bottom of the sidebar. Open Linux, right-click
Ubuntu/Debian (x86, headless), and copy the link.
3
Paste the setup script
<FORMAL_ENDPOINT_PACKAGE_URL> with the copied link. To upgrade
the Endpoint, copy the link again and update the script.4
Add the check script
formal auth whoami
succeeding means that new CA is already on disk. If the agent is not
running after a reboot, the check fails and setup starts it again.5
Save and apply
Save the manifest. New computers apply it on start. To apply it now, open
Grok Bot → Settings → Updates → Reset, or recreate the
computer from the dashboard.
formal auth whoami should show the machine user that owns the API key.
Transparent Mode should be enabled.
Create the network rule
The Endpoint forwards a connection unless a network rule matches. This rule terminates TLS for Gmail so policy can run.- Control Plane
- Terraform
- Navigate to Network Rules
- Create a rule named
gmail-grok-bot - Paste the CEL below
- Leave Forward to Connector unset
- Save the rule and set it to Active
&& user.id == "<MACHINE_USER_ID>" to pre_tls.
Create the Gmail policy
Block every HTTP request to those hostnames. Create the policy in and set it to Active.- Control Plane
- Terraform
- Navigate to Policies
- Click Create Policy
- Name it
block-grok-bot-gmail - Paste the Rego below
- Save and set the policy to Active
Verify Gmail is blocked
Ask a Bot to openhttps://mail.google.com in the computer browser. Chrome
should show Formal’s block page with a policy ID, session ID, and request ID.
Also try https://gmail.com. Both hosts should block.
Open Logs. Filter to Endpoint. Confirm the
blocked request hostname is mail.google.com or gmail.com.
Troubleshooting
Team Setup did not install Formal
Team Setup did not install Formal
Confirm the team is on Enterprise and the manifest is saved. Reset the
computer from Grok Bot → Settings → Updates → Reset. Confirm
the Team Secret is named
FORMAL_API_KEY. A computer that belongs to
more than one team does not receive Team Secrets.formal auth whoami fails
formal auth whoami fails
Confirm the agent is running and read its log:Confirm the API key is valid. Reset the computer so Team Setup starts
the agent again.
Chrome shows a certificate warning
Chrome shows a certificate warning
Confirm
/etc/opt/chrome/policies/managed/formal-localca.json exists. The
check script rewrites it from the live Formal CA after the agent
starts. Reset the computer if Team Setup has not run since boot.
Restart Chrome after that. Do not disable TLS verification.The policy does not evaluate
The policy does not evaluate
Confirm the policy and the Gmail network rule are Active. Confirm
Transparent Mode is enabled. Without a matching rule, the Endpoint
forwards Gmail without inspecting it. Confirm Grok Bot’s own network
policy allows
mail.google.com.Next steps
Linux Endpoint
Review the headless package and systemd service
Network Rules
Select which traffic Transparent Mode intercepts
Policy Evaluation
Explore HTTP policy inputs
Endpoint Logs
Review requests and policy decisions