AI
OpenAI Dots Agents Explained: Always-On ChatGPT Agents
October 202612 min read

Dots are always-on ChatGPT agents that OpenAI announced at DevDay on 29 September 2026. Each dot runs on GPT-6 Astra, works from its own cloud computer and browser, and connects to over 4,000 apps through plugins. Unlike a chat, a dot keeps working towards your goals between conversations and brings results back for review.
Dots are rolling out to ChatGPT Pro and Business Premium users in eligible markets, and Enterprise, Edu and Healthcare workspaces can try a beta once an admin enables it. The first dot is included in Pro or Business Premium at no extra cost, with extended limits for deeper work in the first month. Prices for additional dots and higher speed have not been published.
OpenAI did not announce a dots endpoint; dots are described inside ChatGPT, Slack and Microsoft Teams. Developers who need an always-on agent in their own systems can build one on the Agents API, which gained computer use and multi-agent orchestration at DevDay 2026. In that case you own the scheduler, state and approvals yourself.
Dots have built-in tiers: password changes and money transfers are handed back to you, while permanent deletions and new security-sensitive access are confirmed every time. Custom Rules let you allow, require approval for, or block other supported actions. Auto-review is a separate check that runs before actions such as sending an email and can block a step the dot cannot override.
A dot keeps context from connected plugins for as long as the dot exists, and individual memories cannot currently be viewed or deleted, only the whole dot. OpenAI also says its prompt-injection protections reduce the risk but do not eliminate it. Use dots for read-heavy work around the ERP, keep postings and payments in the ERP's own approval workflow, and involve whoever owns data protection compliance first.

Key Takeaway
OpenAI Dots are always-on ChatGPT agents announced at DevDay on 29 September 2026. Each dot runs on GPT-6 Astra with its own cloud computer and browser, connects to over 4,000 apps through plugins, and keeps working between conversations, while Custom Rules, Auto-review and mandatory handoffs govern what it may do without asking.
Most AI agents still stop when the chat window closes. OpenAI Dots agents are built not to. Announced at DevDay 2026 in San Francisco on 29 September, a dot is a persistent ChatGPT agent powered by GPT-6 Astra that has its own cloud computer and browser, connects to the apps you approve, and keeps working towards the goals you set while you are doing something else.
This post separates what OpenAI has actually published, in its announcement, its safety write-up and two Help Center articles, from what launch-week coverage reported. It then looks at dots the way an engineer should: how they differ from a chat or a Codex task, which controls are real, and how a business with an ERP back-office could pilot one without handing it the keys.
OpenAI describes dots as remarkably capable, always-on agents built to handle everything. Stripped of the slogan, the announcement commits to four concrete properties:
Getting one is deliberately narrow at launch. You create your first dot in the ChatGPT desktop app or a desktop browser, give it a name and connect apps; only after that initial setup can you message it from the mobile app. OpenAI calls this your primary dot, says it envisions teams of dots working together later, and is previewing specialist dots for organisations.
Launch coverage moved faster than the documentation, and several claims drifted. The table sets OpenAI's published wording against what outlets reported, so you know which details are safe to plan around.
| Topic | What OpenAI publishes | What coverage reported | What to plan on |
|---|---|---|---|
| Channels | ChatGPT on desktop, web and mobile, including voice calls, plus Slack and Teams; texting coming soon | Business Standard listed text messages, email and Slack | Texting is not live yet. Email is an action through connected apps, not a channel in OpenAI's list |
| Plans | Rolling out to Pro and Business Premium in eligible markets; Enterprise, Edu and Healthcare can try a beta once an admin enables it | Several explainers reported that the Pro rollout excludes the EEA, Switzerland and the UK | Check OpenAI's eligible-markets list for your country before promising anyone access |
| Price | First dot included at no extra cost, plus an allowance for deeper work with extended limits in the first month | Prices for extra dots, higher speed and specialist dots were not disclosed | Budget only for the included dot today |
| Usage limits | Conversations with a dot do not count towards ChatGPT limits; Codex or ChatGPT Work tasks it starts do | Often summarised as unlimited use | Not unlimited: delegated work is metered as usual |
| Delegation | Activity View shows ongoing and delegated tasks; teams of dots are a stated future vision | Described as delegating work to sub-agents | Delegation exists today; coordinated teams of dots do not yet |
| Developer access | Dots are described only inside ChatGPT, Slack and Teams, with no dots endpoint announced | Some explainers state outright that dots have no public API | Build on the Agents API if you need an always-on agent in your own system |
| Age | Not available to users under 18 | Rarely mentioned | Confirmed in the Help Center |
The pattern is consistent: coverage rounds up. Channels that are coming soon get reported as live, metered work gets reported as free, and a future vision of dot teams gets reported as a shipped feature. When a detail drives a decision, trust the Help Center wording over the headline.
The useful mental model is ownership of time. A chat answers while you are present. A Codex Cloud task runs in an isolated environment and then finishes. A dot holds a goal open indefinitely and decides for itself when there is something worth doing.
| Dimension | ChatGPT chat | Codex Cloud task | Dot |
|---|---|---|---|
| Lifetime | One conversation | One task, which keeps running while your laptop sleeps | As long as you keep the dot |
| Who starts work | You, every turn | You, once per task | You, or the dot itself through proactive research and recurring automations |
| Environment | None of its own | An isolated environment with that task's repositories, tools and dependencies | A persistent sandboxed Linux cloud computer with Chrome, plus your laptop if you connect it |
| Memory | ChatGPT Memory | The task's own context | Its own context plus shared ChatGPT Memory, cleared only by deleting the dot |
| Control | You read every reply | Sandbox and approval policy | Custom Rules, Auto-review, mandatory handoffs and Activity View |
For developers this matters because a dot is a product, not a primitive. OpenAI announced no dots endpoint. If you need an always-on agent inside your own system, the DevDay additions to the Agents API, such as computer use and multi-agent orchestration, are the building blocks, and you own the scheduler, the state and the approvals yourself.
Dots do not run on a single allow-or-deny switch. OpenAI's safety write-up describes three tiers of built-in action rules, and Custom Rules can only move actions inside the tiers that are not mandatory.
Sharing has its own rule. Authorisation must cover both the information and the type of recipient: health data always needs a named recipient, while less sensitive data such as an email address defaults to a class of recipient, such as any airline, which a Custom Rule can widen. That authorisation stays tied to the task; continuing later or delegating work does not expand it.
Before an action such as sending an email or changing a file, a separate system called Auto-review checks the planned step against your instructions, your Custom Rules and OpenAI's safety requirements. If it blocks, it tells the dot why, and the dot asks you, tries a permitted alternative, hands the step back or stops. The enforcement sits outside the environment the dot can change, so the dot cannot switch the check off. Writing your rules down before you open the settings screen keeps them deliberate:
# dot-rules-worksheet.yaml: a planning sheet for ONE dot.
# NOT an OpenAI config format. Transcribe it into Custom Rules by hand,
# so every rule is a decision someone made, not a default nobody read.
dot: finance-assistant
owner: ar-team-lead@example.co.id
connected_plugins: # read-heavy, and nothing the job does not need
- accounting-mailbox
- shared-drive/ar-reports
allow_without_asking:
- read: accounting-mailbox, shared-drive/ar-reports
- draft: payment-reminder emails # drafting is not sending
require_approval:
- send: payment-reminder emails # every batch, until trust is earned
- share: customer statements # name the recipient, not "anyone"
block:
- send: any email to a domain not already in the thread
- share: anything from the payroll folder
# Built in by OpenAI, whatever you write above:
# change a password, transfer money -> handed back to a human
# permanent delete, unrecognised software,
# new security-sensitive access -> confirmed every time
# proactive research -> read-only, enforced in codeThe worksheet is a planning document, not an OpenAI file format: you enter the result through Custom Rules in settings. A dot can help draft rules, but it needs your approval to change them, and no rule can remove a mandatory confirmation or handoff.
The feature that makes a dot feel always-on is proactive research. When you are not working with it, the dot starts background tasks that read permitted connected sources and save private notes for itself. OpenAI says the limits are enforced in code: research tools cannot send messages to other people, change content in connected apps or control a browser or computer, and any follow-up action goes through the normal rules and Auto-review.
That split is a sensible answer to the obvious attack. An always-on agent that reads your inbox will eventually read an email written to manipulate it. OpenAI's Help Center is candid here: its protections, including teaching the dot to distinguish your instructions from content it encounters, reduce the risk of malicious instructions causing an unwanted action but do not eliminate it.
Content is not permission
A dot that reads supplier emails, web pages or shared documents is reading text an outsider can write. OpenAI says such content does not grant permission on its own, but the safeguards are probabilistic. Keep send, share and edit actions behind approval for any dot whose inputs include external mail or the open web, and never paste secrets into a chat or document: the secure sign-in protection covers supported login forms only.
For Enterprise workspaces, OpenAI's admin article lists four dots permissions, and three of them are documented as off by default. That default is the most important fact for an IT team: nothing happens until someone opts in.
| Setting | What it controls | Enterprise default |
|---|---|---|
| Use dots (Beta) | Whether members can use dots at all | Off |
| Add dots to Slack and Microsoft Teams | Lets a dot join supported workspaces and post with its own identity | Not stated; members still complete setup themselves |
| Allow local computer access | Lets a dot use local files and run commands, while the member's computer is connected, online and running the ChatGPT app | Off |
| Use custom rules for dots | Lets members add or edit the rules that guide their dot's actions and confirmations | Off |
Separate cloud computer capabilities, namely cloud browser use, cloud network access and cloud computer use, plus a distinct password manager control, apply to dots and Work Cloud tasks alike, even when Work is disabled. Two details catch teams out. A dot's cloud computer does not inherit a member's VPN, browser sign-ins or device policies, so intranet systems behind a VPN are simply out of reach. And disabling custom rules does not make every action require approval, because the default action rules still apply.
Pilot with custom rules switched on
Because custom rules are off by default in Enterprise, a pilot group without them runs on OpenAI's defaults alone. Enable the setting for the pilot group so each user can tighten those defaults, for example by blocking outbound email entirely for the first weeks.
OpenAI's own examples point at back-office work. An early tester's dot noticed a forgotten invoice, prepared it and sent it after approval, and the specialist dots preview builds on internal testing across procurement, invoice processing, email marketing, customer support and commercial contracting. Specialist dots get their own identity, credentials and access to a company's systems of record, start as focused enterprise pilots run with OpenAI engineers, and are being integrated with Microsoft Agent 365 for governance.
Consider a mid-sized Indonesian distributor that runs its finance on an ERP. A personal dot fits the work around the ledger: watching the AR mailbox, drafting payment reminders in each customer's register, turning an exported aging report into a summary for the Monday meeting. It fits the ledger itself poorly. Posting journals, releasing payments and changing vendor bank details are exactly the actions the built-in rules hand back or confirm, and they belong in the ERP's own approval workflow, where the audit trail lives.
Data handling deserves the same scrutiny. A dot retains context from conversations and plugins for as long as the dot exists. You cannot currently view, delete or edit individual dot memories, disconnecting a plugin does not remove what the dot has already learned, and the only way to clear its context is to delete the dot. Business, Enterprise and Edu content is not used for training by default; on personal plans the Improve the model for everyone setting decides. For a company bound by Indonesia's personal data protection law, connecting a dot to customer data is a decision for whoever owns compliance, not a toggle to flip during a pilot.
The included allowance has extended limits for the first month after launch. That makes the first month the natural pilot window, and also a misleading one for estimating long-run cost. A disciplined pilot looks like this:
If the pilot holds up, the next question is whether the responsibility should stay with a personal dot or move to a specialist dot with its own identity, which is where OpenAI is steering organisational use.
Dots change who holds the goal. A chat waits for you; a dot keeps the goal open, reads your connected apps in the background and acts within rules you can inspect. Treat one like a new colleague with read access on day one: write its rules down, keep consequential actions behind approval, and widen trust only on evidence.