Evidence record / grok-build
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onl
Enterprise enforcement: signed requirements.toml, model restriction, enforced and managed-only hooks. Org policy gained a signature, a model allowlist, a managed-only hook switch, and a pre-write MCP/marketplace block.
Channel: tagged-release. Half: both. Date: 2026-09-01 (1.0.16), 2026-09-02 (1.0.18), 2026-09-17 (1.0.36).
Operator consequence: Admins: set fail_closed = true, or a user can edit ~/.grok/requirements.toml and turn enforced hooks back into ordinary ones. The signed file only binds on the enterprise channel build you actually shipped; check which version that pointer serves (1.0.35 at observation, which predates the “Enforced hooks” doc and the 1.0.36 managed-only switch).
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onl
Profile citations
- grok-build / claim / enterprise-signed-requirements
Source links
Primary links, including exact changelog lines when available.
- tagged commit file2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onlxai-org/grok-build / crates/codegen/xai-grok-shell/changelogs/1.0.16.mdtagged commit file2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onlxai-org/grok-build / crates/codegen/xai-grok-pager/docs/user-guide/10-hooks.md#L234
Versioned source: run artifact