Finding / grok-build

2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onl

Enterprise enforcement: signed requirements.toml, model restriction, enforced and managed-only hooks. Org policy gained a signature, a model allowlist, a managed-only hook switch, and a pre-write MCP/marketplace block.

Channel: tagged-release. Half: both. Date: 2026-09-01 (1.0.16), 2026-09-02 (1.0.18), 2026-09-17 (1.0.36).

Operator consequence: Admins: set fail_closed = true, or a user can edit ~/.grok/requirements.toml and turn enforced hooks back into ordinary ones. The signed file only binds on the enterprise channel build you actually shipped; check which version that pointer serves (1.0.35 at observation, which predates the “Enforced hooks” doc and the 1.0.36 managed-only switch).

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-grok-build-enterprise-enforcement-signed-requirements-toml-model-restriction-enforced-and-managed-onl

Profile citations

  • grok-build / claim / enterprise-signed-requirements

Source links

Primary links, including exact changelog lines when available.