DVx Signal/Builder/Issue 004
Builder004
Technical intelligence for builders

The agent desktop became persistent

Grok Bot put durable teammates on a shared cloud computer, Google added identity and revocation to Workspace Studio, Gemini 3.7 Flash launched, and Codex reached GitLab.

5 min readPrimary sources firstVerified August 23, 2026

Four changes to make before your next agent run

Google gave no-code agents identities, audit trails, and a stop button. Gemini 3.7 Flash launched with a temporary half-price rate. Grok Bot put persistent AI teammates on a shared cloud computer. Codex reached GitLab.

The question is whether you can identify an agent, limit it, stop it, and reconstruct what it did.

Google gave no-code agents identities, stops, and logs

A Workspace Studio agent identity passes through approval, revocation, suspension, and DLP controls into an auditable workflow.

DVx control map based on Google’s August 17 Workspace Studio announcement.

What changed

New Workspace Studio flows can run under least-privileged identities. Admins can attribute actions, revoke OAuth scopes, suspend flows, gate external sharing, and apply DLP on eligible plans.

Why you should care

A no-code flow can now look more like a managed service account. Existing flows do not inherit the controls yet.

What to do next

Create one low-risk flow. Remove a permission, suspend it, and save the visible events in workspace-flow-control-record.md.

The control plane

The new-flow boundary is the decision

The controls matter because they can stop one workflow without revoking a person’s whole account.

Identity
Least-privileged identity for newly created flows first.
Attribution
Unique ID and flow context in audit events during the beta rollout.
Stop
Revoke a selected OAuth scope or suspend the flow.
Data
Approval gates and DLP on eligible higher-control plans.

The decision: test the identity, stop mechanism, and log together before using the flow on production data.

Primary source: Google Workspace. Verified August 23, 2026. Controls apply to newly created flows first. DLP availability varies by plan.

Primary sourceGoogle Workspace Studio security controls.

Gemini 3.7 Flash launched with a price-expiry date

A fixed Gemini 3.7 Flash workload costs fifteen cents through December and thirty cents from January 1.

DVx cost comparison using Google’s published API rates and one fixed workload.

What changed

Gemini 3.7 Flash became generally available on August 13. Standard API rates are $0.75 per million input tokens and $3.75 per million output tokens through December 31. Both double on January 1, 2027.

Why you should care

A cheap December pilot can have a different January budget.

What to do next

Compare one task with your current model. Record success, tokens, latency, and cost in model-cost-and-quality.csv.

Same workload · 100k input + 20k output

The standard rate doubles on January 1

Gemini BatchThrough Dec 31
Input + output
$0.075
$751,000 runs
Gemini StandardThrough Dec 31
Input + output
$0.15
$1501,000 runs
Gemini StandardFrom Jan 1
Input + output
$0.30
$3001,000 runs
Claude Sonnet 5Standard API
Input + output
$0.40
$4001,000 runs

The decision: use the January rate in a recurring forecast unless the workload ends first.

Primary sources: Google and Anthropic pricing. Verified August 23, 2026. Output includes thinking tokens. Holds token counts constant. Excludes quality, caching, tools, grounding, regions, subscriptions, and discounts.

Primary sourcesGemini API changelog; Gemini pricing; Anthropic pricing.

Grok Bot made the agent desktop persistent

Three named Grok Bots share one persistent cloud computer containing files, browser sessions, and logins.

DVx boundary map based on xAI and Cursor’s Grok Bot documentation.

What changed

Grok Bot launched August 11. Named agents get a persistent cloud computer, browser, terminal, app sessions, memory, and routines. They coordinate and keep working after your laptop closes. Access expanded August 21 across eligible Grok and Cursor plans.

Why you should care

Every Bot owned by one user shares its computer, files, browser sessions, logins, and local permissions. Separate Bots are not security boundaries.

What to do next

Pilot one read-only job with a new account and no local access. Record sessions, approvals, routing, data settings, spend, and cleanup in grok-bot-boundary-record.md.

The actual security boundary

One user gets one shared computer

Named teammates are separate working contexts, not separate credential zones.

Storage
Cloud storage is required. Legacy Privacy Mode is unsupported.
Actions
Approval rules and Auto Review exist. Least privilege still matters.
Models
Product-managed routing and failover. No admin model picker.
Oversight
Action audit view and Bot-specific spend cap are still coming.

The decision: scope credentials to the user’s whole Bot roster, then keep consequential actions behind approval.

Primary sources: xAI and Cursor. Verified August 23, 2026. The August 11 launch was missed in Issue 003. The August 21 access expansion falls after this issue’s core research window.

Primary sourcesGrok Bot launch; access expansion; security and privacy; team controls.

Codex reached GitLab

A GitLab issue triggers Codex cloud, which returns a merge request for human review.

DVx workflow map based on OpenAI’s August 19 GitLab beta announcement.

What changed

The August 19 beta lets every ChatGPT plan connect GitLab to Codex cloud. @codex can start from an issue or merge request and review the result.

Why you should care

GitLab teams get an issue-to-agent-to-MR loop without moving repositories. Self-Managed installations need admin setup and GitLab 19.0 for webhooks. Reviews can fail when GitLab omits oversized diffs.

What to do next

On one small repository, record cloud execution, webhook permissions, branch rules, diff coverage, and reviewer in codex-gitlab-pilot.md.

Primary sourcesOpenAI product release notes; Codex plan guide.

One workflow to try · 30 minutes

Run a Grok Bot boundary test

  1. TaskGive one Bot a read-only, reversible research task.
  2. ApprovalStop sending, publishing, deleting, and local commands.
  3. InspectCheck cloud files, browser session, actions, and usage.
  4. Clean upRemove files, sign out, and revoke the connector.

Keep the task, evidence, approval, and cleanup record.

Portfolio watchlist

Three checks before the next run

Engineering

GPT-5.6 Sol Ultrafast reports up to 750 output tokens per second. Access is limited and price is missing.

Data

OpenAI previewed cross-session safety processing for ZDR customers. Keep today’s endpoint matrix until the September paper arrives.

Education

ChatGPT for Teens adds safeguards and parent links. Test classification and escalation.

Term of the week

Agent identity

A distinct identity used by an automated workflow, with its own permissions and audit trail. It lets you stop the workflow without revoking a person’s entire account.

Field Manual impact

Manual 02 changes

The Overnight Build should add the Grok Bot shared-computer boundary, cloud-storage requirement, approval rules, cleanup procedure, and missing action audit and spend cap.

Source ledger

DevelopmentAnnouncedAvailable or effective
Workspace Studio controlsAugust 17New admin controls from August 17. End-user actions from August 20. Existing flows later.
Gemini 3.7 FlashAugust 13Generally available August 13. New price January 1, 2027.
Grok BotAugust 11Early beta August 11. Access expanded August 21.
Codex for GitLabAugust 19Beta August 19.
Verification notes
  • Core research covered August 13 through August 19. Selected links were checked August 23.
  • Announcement, availability, rollout, and scheduled-price dates are separate.
  • Workspace Studio controls cover newly created flows first.
  • Gemini’s January rate is scheduled. The chart compares APIs, not seats or subscriptions.
  • Grok Bot requires cloud storage. All Bots owned by one user share one cloud computer and its files, sessions, and logins.
  • Grok Bot’s August 11 launch was missed in Issue 003. The August 21 access expansion is outside the core window.
  • Codex runs in its cloud. GitLab setup and diff limits are explicit.
  • No confidential portfolio information is included. The published copy contains no em dashes.