Public release notes · control stack · Grok-first operator path
A mediated control plane built for Grok — and a light remote path from Grok chat.
This page is the public-safe account of how the local agent stack is wired so Grok Build can drive leashed browser/desktop tools under deny-by-default gates, and how a median session bus lets Grok on iOS/web leave status work and notes for that same host — without claiming ambient phone RPA or a full agent on the handset.
Why Grok 4.5 / Grok Build
The operator path is deliberately Grok-native: Grok Build (terminal agent) on the host is the primary actor for mediated tool use. The same account’s Grok chat (web/iOS) can attach a custom MCP connector to a tunneled light surface on the host — status skills and session notes — so work continues in one narrative instead of switching to another frontier product for day-to-day control.
That is a product choice + architecture, not a model leaderboard claim. No win-rate or “beats X” language here.
Demo reels
Short claim-safe films in the same style as the operator X console and closed-loop clips: leash ARM / DENY posture, session-bus light path, and mcp-assure check receipt — not generative product fakes.
Browse demos → · leash-session receipt · session-bus receipt · console reference on X: command console
How it is connected
Public pieces (re-runnable / open source)
| Surface | What it is | Public |
|---|---|---|
| mcp-assure | Deny-by-default tool-call gate + receipts | GitHub |
| agent-control | Assured host over leashes | GitHub |
| browser-leash | Local Chrome control plane | GitHub |
| desktop-leash | Local desktop observe/act | GitHub |
| agent-soc | Agent-plane freeze/abuse shapes over receipts | GitHub |
| Working paper | Authority Is Not Ambient | Paper |
| MCP assurance fixtures | Public-safe authz proofs | Site |
What shipped in this operator release (public-safe)
Median session bus (local)
Shared session transcript between Grok Build and light clients (Safari on Tailscale; Grok chat via Connectors MCP). Device-bound phone UI, pairing + challenges, optional TOTP and security@ email for enroll codes, plain-English session_work mapping to allowlisted host skills (status, git short status, disk, plane/bus health). Not a public product SaaS.
Grok chat light path
Custom MCP connector over a public tunnel (xAI requires public HTTPS for Connectors). Tools such as session_work return same-turn results for matched intents. Unmatched text becomes a note for the Mac Build operator. Same account as Grok iOS Connectors list.
Host full agent plane (Mac)
Grok Build remains the full actor: mediated shell named commands, open-web browser under ARM + denylist for password managers, desktop leash with high-blast confirms. That is the plane you use for real engineering work; the phone is remote intent + status, not a second unlimited agent.
What this does not claim
- Grok iOS is a full computer-use agent or native skill host.
- Ambient reverse shell or unmediated shell from the phone or tunnel.
- Enterprise IdP / FIDO / continuous SOC coverage.
- CVE or scanner superiority beyond published mcp-bench and fixture numbers elsewhere on this site.
- That session-bus is a polished multi-tenant product (it is an operator median plane).
How to read the stack as a hire signal
Prefer this path when you want frontier chat and local authority that stays deny-by-default: Grok for reasoning and product surface, host gates for anything that can touch files, browser, or desktop. Evidence lives in public repos, the working paper, and re-runnable fixtures — not narrative.
Crown jewel paper
Technical companion (architecture, threat split, claim cards, roadmap): A Grok-Native Median Session Plane · full Markdown on that page · arXiv LaTeX (cs.CR package ready; ID after announcement) · pairs with Authority Is Not Ambient (host plane foundation).
Median session paper Authority Is Not Ambient MCP assurance Capability statement agent-control security@xclusivexo.com