← 一覧に戻る
Grok活用事例ダイジェスト
2026-09-30・仕様2 / 新機能2 / 実践2 ※英語は日本語訳つき。本日は昨日ギャップだったTeam Bots運用ヘルプを中心に、秘密の安全な保存、セキュリティのIdentity/Prompt injection、マルチプロジェクト運用ガイド、Post-Sales公式プレイブック、まさお3鉄則(AI氣道)を取り上げています。公式Product新着はTeam Bots(9/28)以降なし。Xスクショは取得していません。
仕様解説
cursor.com/help — Store secrets securely(秘密の保存)en仕様
引用
Keep API keys and other credentials out of chat and ordinary files. After you save a secret, Grok Bot does not show the value again. A blank field later is not proof the secret was deleted. … Use the secure secret card when a Bot asks for one. The field is masked. Choose Save securely. … The value is not written into the chat. … Don't paste secrets into chat, Shell, or ordinary files. Don't type them into a demonstration when you use Teach a task. … Secrets on a Bot are yours. On a Team Bot you own, secrets are used in every teammate's chat, so only add keys you're happy for the whole team to use. … That is expected. Saved values are write-only. … Recover, Reset, and computer updates remove installed apps and packages. A secret you typed into a file, a shell profile, or an installed tool on the computer can disappear with that. That is separate from Secrets. If the name is still listed under Secrets, the value is still stored.
日本語訳
APIキーなどの資格情報は、チャットや通常のファイルに置かないでください。保存したあとは値が再表示されません。あとで空欄に見えても、削除された証拠にはなりません。Botが求めたときはセキュア秘密カードを使い、マスクされた欄に入れて Save securely します。値はチャットに書かれません。チャット・Shell・通常ファイルへの貼り付けや、Teach a task のデモ中の入力は避けます。個人Botの秘密は自分のものですが、自分が所有するTeam Botに載せた秘密はチーム全員の会話で使われるので、共有してよいキーだけにしてください。保存値はwrite-onlyです。Recover/Reset/コンピュータ更新で消えるのは、ファイルやシェル設定に書いた側の秘密で、Secrets一覧に名前が残っていれば値は残っています。
コメント
考察
デモではチャット貼り付けを禁止し、Secretsに名前だけ見せて「値は戻ってこない」ことを一緒に確認すると、運用の型が伝わりやすいです。確信度: 公式help。
Store secrets securely · Team Bots
docs.x.ai — Grok Bot security(Identity and sign-ins/Prompt injection)en仕様
引用
A Bot has no identity or credentials of its own: Bots act as the signed-in member. A Bot can never hold more access than the person it belongs to, every action stays attributable to a named member, and there is no separate machine identity outside your identity provider to provision, rotate, or audit. Team-managed connectors are the one exception: they may use team or service-account credentials. Connector tokens stay on Cursor's backend. Bots invoke tools without receiving OAuth tokens, and tokens are never stored on the computer. Credentials stay with the member. For login, two-factor, and payment steps, the Bot hands the computer to the member rather than typing credentials. … Content a Bot reads from the outside world, like web pages, plugin results, and command output, can try to steer it. Grok Bot layers defenses: Auto Review checks Bot actions against the member's request when enforcement is on, and beneath it sit controls that do not depend on any model's judgment, including the network policy, per-action approvals, and per-user isolation. Outside content is marked as untrusted data when presented to the model. These controls reduce, but do not eliminate, risk from malicious content, which is another reason to keep consequential actions behind approval.
日本語訳
Botには独自の身分や資格情報はありません。Botはサインインしたメンバーとして動き、その人以上の権限は持てず、操作は常に名前付きの人に帰属します。IdPの外に別の機械身分を用意する必要もありません(チーム管理コネクタがチーム/サービスアカウント資格情報を使う例外はあります)。コネクタのOAuthトークンはCursorのバックエンドに留まり、コンピュータ上には置かれません。ログイン・二要素・決済はTake overで人が入力します。一方、Webページ・プラグイン結果・コマンド出力など外部から読んだ内容は、Botを誘導しようとすることがあります。Auto Review、ネットワークポリシー、操作ごとの承認、ユーザー分離が重なり、モデルへの提示では外部内容がuntrustedとして印付けされます。リスクはゼロにはならないので、影響の大きい操作は承認の後ろに置きます。
コメント
考察
パイロットでは読み取りと下書きに限り、送信・購入・本番変更は必ず承認ゲートに置くと説明が短く済みます。確信度: 公式docs。
Grok Bot security · Security FAQ
新規機能解説
cursor.com/help — Team Bots(運用ヘルプ:作成・Publish・Slack・承認)en新機能
引用
A Team Bot is a Bot one person owns and publishes to their Cursor team. After it's published, everyone on the team can chat with it. Each person's chat with a Team Bot is private. Team Bots always run in the cloud. A Bot that runs on your own computer can't be a Team Bot. … Choose New → Create new Team Bot. … It asks for plugins, then secrets, then files. Only add keys and files you're happy for the whole team to use. … Teammates can't see a Team Bot that still has the default name and no description. … Publish to team. … Can the owner see my chats with a Team Bot? No. … When you chat with a teammate's Team Bot, the chat uses your Grok Bot usage, not the owner's. … A Team Bot asks for approval only in its owner's own chat with it. In teammates' chats, in Slack, and in group chats, nobody who can answer an approval card is there. So the Bot works within the permissions its owner set up, without stopping to ask. It still asks before it uses your personal accounts. … How do I add a Team Bot to Slack? The owner adds it, after publishing … Bring to your team's Slack → Connect. … Each teammate needs to link their Slack account first. … Create, publish, edit, and connect Team Bots to Slack on desktop. You can't start a voice call with a teammate's Team Bot.
日本語訳
Team Botは一人が所有し、Cursorチームへ公開するBotです。公開後は全員が話しかけられますが、各人の会話はプライベートです。Team Botは常にクラウドで動き、手元PC実行のBotはTeam Botになれません。New → Create new Team Bot で作り、プラグイン→秘密→ファイルの順で整えます。チーム全員に使わせてよいキーとファイルだけを入れます。デフォルト名のままではチームに見えません。Publish to team で公開します。所有者は他人の会話を読めません。チームメイトのTeam Botへの会話は自分の利用枠を消費します。承認カードは所有者本人の会話だけに出ます。チームメイト会話やSlackでは承認待ちに止まらず、所有者が設定した権限の範囲で進みます(個人アカウント利用の前には確認があります)。Slack接続は公開後に所有者が行い、各メンバーは Settings → Team Bots でSlackをLinkします。作成・公開・編集・Slack接続はデスクトップ向けで、他人のTeam BotとのVoice callはできません。
コメント
考察
初回は読み取り専用コネクタと下書きまででPublishし、Slackはオーナー接続とメンバーLinkを分けて説明するのが安全です。確信度: 公式help。
Team Bots(Help) · 発表ニュース(9/28)
x.ai/bot/guides — How I run multiple teams of Grok Bots(案件チャネル運用)en新機能
引用
Each project gets a channel, a roster, and a Notion board. An experimental pattern for coordinating bots like a human team. … Most of the time I run my Grok Bots as separate chats. … That's all fine until you need to juggle a couple of different projects at the same time. … So I replicated that. Each project gets a Grok Bot channel and an entry in a Notion database. Note that this is an experimental pattern I'm still trying out. … I created two databases in Notion, Projects and Tasks. Then I created a projects (plural) Manager bot. … It has a Project Ops skill that takes care of creating a project, opening a channel, and staffing it with the right bots. … Staffing rules I added: Reuse existing bots first. … Propose at most five bots besides the PM. Each channel is limited at six bots … Create a new bot only when nothing on the bench fits, and only after I say yes. … When a bot gets stuck, or needs more input, it'll mark its task as Blocked and then ping me in the channel.
日本語訳
各プロジェクトにチャネル、ロスター、Notionボードを用意します。人間のチームのようにBotを協調させる実験パターンです。普段はCoder/Writer/Researcherを別チャットで動かしますが、複数案件を同時に抱えると信号と雑音の切り分けが難しくなります。そこで、プロジェクトごとにGrok BotのチャネルとNotionの行を作りました(まだ試行中です)。NotionにProjectsとTasksの2DBを置き、複数プロジェクトを束ねるManager Botを作ります。Project Opsスキルが、案件作成・チャネル開設・適切なBotの配置を担当します。配置ルールは、既存Botの再利用優先、PM以外は最大5体(チャネル合計6体まで)、新規作成は既存が合わないときだけ・しかも自分の承認後、です。行き詰まったBotはタスクをBlockedにしてチャネルで自分を呼びます。
コメント
考察
Roster上限と「新規Botは人がYesしてから」を最初のルールにすると、Bot増殖を抑えやすいです。確信度: 公式Guides(著者の実験パターン)。
How I run multiple teams of Grok Bots
実践事例
Blake Schuller — Grok Bot for Post-Sales(Gus統括+約束管理)en実践
引用
How I run post-sales with one chief of staff bot, account specialists, and routines that prep calls and keep promises from slipping. … What's hard isn't the customer relationship, it's the context. … I only manage one bot. His name is Gus. Gus is my chief of staff, and he manages everyone else so I can keep the parts of the job I love: the relationships, the strategy on each account, face time, deciding what matters today, and the final yes on anything that goes out with my name on it. … Gus exists because I tried running twenty agents myself first, and it was overwhelming. … Behind Gus sits a bench of bots … Follow-ups … Account specialists, one per account … Ink writes emails and Slack messages that sound like me. … Days go by where I don't open a single one of those chats. They remember my directions, they report to Gus, and Gus decides what actually needs me. … Unfinished promises, at 9, 1, and 4. Things I said I'd do … It never replies for me. … I still do all the relationship work. … I didn't automate my job. I stopped spending the first hour chasing context. … I started with a voice memo of my day. … Then send that over to your bot and ask it to build you a system that makes your life easier.
日本語訳
Post-Salesを、チーフオブスタッフBot1体とアカウント担当、約束が抜けないRoutinesで回す話です。難しいのは顧客関係そのものより文脈の追い直しです。著者が直接見るのはGusだけで、関係・戦略・対面・今日の優先・自分の名前で出る最終Yesは人が持ちます。最初に20体を自分で回してパンクした経験から、統括1体に集約しました。Gusの下にFollow-ups、アカウント専門、文体担当Inkなどが並び、日によっては下位チャットを開かず、Gusが「今必要なこと」だけを上げます。未完了の約束は9時・13時・16時に洗い、返信の代行はしません。仕事を自動化したのではなく、朝一時間の文脈集めをやめた、という整理です。始め方として、自分の一日をボイスメモで話し、それをBotに渡して仕組みを組ませる提案もあります。
コメント
考察
初回デモはDaily briefとUnfinished promisesの2本だけにすると、成果が見えやすいです。確信度: 公式Guides。
Grok Bot for Post-Sales
AI氣道(田中啓之) — まさお3鉄則(役割分離・メモリ・ルール単一ファイル)ja実践
引用
2026.09.28 … まさおさんの鉄則は「任せる前に、線を引く」話でした。… 3行でわかるポイント … 1. Botは役割ごとに分ける。コンテキストも注意力も有限なので、進行・UI検討・設計・実装・打鍵テストの5体に持ち場を渡します。2. メモリはBotごとに育てる。VMやファイル、ログインは全Botで共通、説明欄とメモリとルーティーンはBotごとです。3. ルールは1つのファイルに置く。「チームのきまり.md」に集めて、各Botの説明欄から参照させます。… 「コンテキストウィンドウは有限で注意力も有限です。だから役割ごとにボットを分けてそれぞれが向ける注意を絞ってあげる。」… 「VMやファイル、ログインは全部のボットで共通。説明欄とメモリ、ルーティーンはボットごとです。」… 「ルールは1つのファイルに置いて説明欄から参照させます。」… ルールを変えたのに、古いルールがメモリに残っていた。対策は、きまりを差し替えたら、業務管理者Botから各Botにメモリを見直させることでした。
コメント
考察
まずは進行・作る・チェックの3体と「やらないこと」各1行から始めると、小規模チームでも再現しやすいです。確信度: JA二次(動画要約+著者メモ)。
AI氣道 — Grok Botの使い方(3鉄則)
収集: 2026-09-30 約05:04–05:35 JST。英語ソースは翻訳付き。公式Product新着は Team Bots(9/28)以降なし。仕様は Secrets と security(Identity/Prompt injection)。新機能は Team Bots運用ヘルプと multiple-teams ガイド。実践は Post-Sales公式と AI氣道(まさお3鉄則)。X(@bot等)は本号もスクショ・embed未取得。1Password vault共有とFinanceの公式手順ページは未確認です。事実と意見を分け、確信度を各カードに記載しています。