Skip to main content

Overview

Grok Bot computers are Linux VMs with a browser and a terminal. Install the Formal Endpoint on every team computer with Enterprise Team Setup. Transparent Mode then evaluates the VM traffic against Formal policy. This guide blocks https://mail.google.com and https://gmail.com. Gmail serves the inbox on both hostnames. A rule that matches only one is bypassed.

Prerequisites

  • A Cursor Enterprise team with Grok Bot Team Setup
  • Outbound HTTPS to api.joinformal.com

Create an API key

Use one machine-user API key for the Grok Bot fleet.
1

Create the key

Go to API Keys and click Create API Key. Assign it to a machine user.
2

Store it as a Team Secret

Open Grok Bot in the Cursor dashboard. Add a Team Secret named FORMAL_API_KEY. Paste the Formal key. Team Setup injects Team Secrets as environment variables. Do not put the key in the setup script.

Install the Endpoint with Team Setup

1

Create a manifest

Go to Grok Bot → Team Setup. Create a manifest, for example formal-endpoint. Add one entry with ID install-formal-endpoint.
2

Copy the package link

In the Control Plane, click Download Formal Endpoint at the bottom of the sidebar. Open Linux, right-click Ubuntu/Debian (x86, headless), and copy the link.
3

Paste the setup script

The Chrome policy trusts the Formal CA. Without it, Chrome shows a certificate warning instead of the Formal block page.Replace <FORMAL_ENDPOINT_PACKAGE_URL> with the copied link. To upgrade the Endpoint, copy the link again and update the script.
4

Add the check script

A zero exit skips setup. After setup runs, Team Setup runs this check again. The check also rewrites Chrome’s Formal CA policy. Headless Linux issues a new CA when the agent starts. formal auth whoami succeeding means that new CA is already on disk. If the agent is not running after a reboot, the check fails and setup starts it again.
5

Save and apply

Save the manifest. New computers apply it on start. To apply it now, open Grok Bot → Settings → Updates → Reset, or recreate the computer from the dashboard.
Verify:
formal auth whoami should show the machine user that owns the API key. Transparent Mode should be enabled.

Create the network rule

The Endpoint forwards a connection unless a network rule matches. This rule terminates TLS for Gmail so policy can run.
  1. Navigate to Network Rules
  2. Create a rule named gmail-grok-bot
  3. Paste the CEL below
  4. Leave Forward to Connector unset
  5. Save the rule and set it to Active
To limit the rule to the Grok Bot machine user, add && user.id == "<MACHINE_USER_ID>" to pre_tls.

Create the Gmail policy

Block every HTTP request to those hostnames. Create the policy in and set it to Active.
  1. Navigate to Policies
  2. Click Create Policy
  3. Name it block-grok-bot-gmail
  4. Paste the Rego below
  5. Save and set the policy to Active

Verify Gmail is blocked

Ask a Bot to open https://mail.google.com in the computer browser. Chrome should show Formal’s block page with a policy ID, session ID, and request ID. Also try https://gmail.com. Both hosts should block. Open Logs. Filter to Endpoint. Confirm the blocked request hostname is mail.google.com or gmail.com.

Troubleshooting

Confirm the team is on Enterprise and the manifest is saved. Reset the computer from Grok Bot → Settings → Updates → Reset. Confirm the Team Secret is named FORMAL_API_KEY. A computer that belongs to more than one team does not receive Team Secrets.
Confirm the agent is running and read its log:
Confirm the API key is valid. Reset the computer so Team Setup starts the agent again.
Confirm /etc/opt/chrome/policies/managed/formal-localca.json exists. The check script rewrites it from the live Formal CA after the agent starts. Reset the computer if Team Setup has not run since boot. Restart Chrome after that. Do not disable TLS verification.
Confirm the policy and the Gmail network rule are Active. Confirm Transparent Mode is enabled. Without a matching rule, the Endpoint forwards Gmail without inspecting it. Confirm Grok Bot’s own network policy allows mail.google.com.

Next steps

Linux Endpoint

Review the headless package and systemd service

Network Rules

Select which traffic Transparent Mode intercepts

Policy Evaluation

Explore HTTP policy inputs

Endpoint Logs

Review requests and policy decisions