{"slug": "xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit", "title": "XMTP Labs CEO says Grok Bot added channel permissions after his bank audit hit Slack", "summary": "XMTP Labs CEO Shane Mac said his personal finance agent, built on xAI's Grok Bot, posted his personal checking and savings balances and major expenses to XMTP's executive Slack channel on October 1st after confusing the channel \"Exec-team\" with his personal group chat \"My Personal Exec Team,\" according to his account published October 9th in Business Insider. Mac said the Grok team told him it shipped a change the night before publication requiring users to explicitly grant agents permission before moving information into other channels, though the account does not specify how the fix was implemented. Mac said he disconnected Google, his calendars, banking and Stripe after the incident, which illustrates that read-only access limits what an agent can do to an account but not where the information it reads can be sent.", "body_md": "# XMTP Labs CEO says Grok Bot added channel permissions after his bank audit hit Slack\n\n**XMTP Labs CEO Shane Mac's October 1st incident was described in a Business Insider account published October 9th. Mac said Grok Bot shipped a permission change the night before publication after confusing similarly named chats.**\n\n        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)\n        · Published \n\nPrimary source: [Business Insider](https://www.businessinsider.com/personal-ai-agent-grok-bot-posted-bank-details-company-slack-2026-10)\n\n## Why it matters\n\nAgents that can read sensitive data and send messages need distinct controls for what they can access and where they can send it. Mac's incident shows how easily a useful workflow can cross a work-personal boundary when those controls are shared or unclear.\n\nXMTP Labs CEO [Shane Mac](https://xmtp.org/?ref=runtimewire) says Grok Bot shipped a permission change after his personal finance agent sent a bank audit to XMTP's executive Slack channel, according to [his account published October 9th in Business Insider](https://www.businessinsider.com/personal-ai-agent-grok-bot-posted-bank-details-company-slack-2026-10?ref=runtimewire). The post itself went up on October 1st, Mac said. It included his personal checking and savings balances and major expenses.\n\nMac said he had given the agent read-only access to his bank accounts and instructed it to send reports only to him through [Grok Bot](https://x.ai/news/introducing-grok-bot?ref=runtimewire). Read-only access limited what the agent could do to the accounts. It did not keep the information it read from being sent somewhere else.\n\nThe agent could reach several connected services, and the names of two destinations looked alike. Mac's personal group chat was called \"My Personal Exec Team.\" The XMTP Slack channel was called \"Exec-team.\" When the agent ran its first monthly audit, it selected the work channel. XMTP's head of product spotted the post and messaged Mac, initially mistaking the report for company financials. A reference to Mac building a barn on his property made clear the figures were personal. Mac said he deleted the message before the agent could do so.\n\n### Separate agents, shared connections\n\nMac had built the \"CFO\" agent around the end of August. Its job was to review balances, expenses and recurring charges, flag suspicious activity and suggest savings. He said he had connected Slack to one of his other agents, but all the agents used the same underlying connections, even though they appeared to be separate. The Grok team traced the misdirected message to the similar channel names, Mac said.\n\nMac said the Grok team told him users would need to explicitly grant agents permission before they could move information into other channels, and that it had shipped a change \"last night.\" That account describes the reported fix but does not specify how it was implemented. The [xAI security documentation, last updated September 16th](https://docs.x.ai/grok-bot/approvals-security-and-privacy?ref=runtimewire), predates the reported change and describes a separate boundary: all of a user's Bots share one cloud computer, including its files, browser sessions and command-line credentials. The documentation says separate Bots should not be treated as a security boundary.\n\nA label such as \"CFO\" names a task; it does not fence off the connected accounts and destinations available across agents. Mac's experience shows the difference between permission to read a source and control over where the resulting information can go.\n\nAfter the post, Mac said he disconnected Google, his calendars, banking and Stripe, among other services. He had been using personal agents for chores he disliked, from following up with the DMV and getting home-service quotes to booking golf sessions. His first finance agent ran weekly without incident, he said; the error surfaced when its monthly audit ran.\n\n### A messaging founder meets the boundary problem\n\nMac has spent much of his career around software that turns messages into actions. He co-founded Assist, a messaging-automation company that [Conversocial acquired in 2019](https://www.prnewswire.com/news-releases/conversocial-acquires-ai-powered-conversational-commerce-platform-assist-300813657.html?ref=runtimewire); Mac then became Conversocial's chief automation officer. XMTP's [account of its founding team](https://blog.xmtp.org/series-a/?ref=runtimewire) describes Mac as having spent 15 years working on messaging and digital communication, and frames XMTP's work around open communication that users can control.\n\nThe agent episode touches the same design problem from another direction. XMTP's thesis puts control over communication in the hands of users and developers. Personal agents add a new actor with access to those conversations and connected services. Giving an agent permission to read a bank account can make a useful monthly report possible; giving it access to messaging can turn that report into an unintended disclosure if the destination boundary is unclear.\n\nMac said the mistake changed how he thinks about the line between work and home. \"There needs to be a much clearer line between personal and work life,\" he wrote in the Business Insider account. In his setup, the same person, same connected agent system and similarly named chats brought those spheres together in one post.\n\nMac still sees personal agents as useful for repetitive administration. His account makes a concrete case for treating permission design as part of the product, with users otherwise left to remember which named agent shares which connections. Read-only access, separate agent names and private destination instructions each address a different part of the task; none alone guaranteed that the report would stay private.", "url": "https://wpnews.pro/news/xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit", "canonical_source": "https://runtimewire.com/article/xmtp-shane-mac-grok-bot-bank-audit-slack", "published_at": "2026-10-09 14:22:39+00:00", "updated_at": "2026-10-09 15:23:11.700249+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-products"], "entities": ["XMTP Labs", "Shane Mac", "Grok Bot", "xAI", "Slack", "Business Insider", "Google", "Stripe"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit", "markdown": "https://wpnews.pro/news/xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit.md", "text": "https://wpnews.pro/news/xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit.txt", "jsonld": "https://wpnews.pro/news/xmtp-labs-ceo-says-grok-bot-added-channel-permissions-after-his-bank-audit-hit.jsonld"}}