Reviewed by Jonathan West · Updated Sep 29, 2026

OpenAI Dots Safety and Account Permissions

What a dot can do on its own, and what stays with you.

Reviewed by Jonathan West · Updated Sep 29, 2026

A ChatGPT dot is safe enough for most work if you keep local computer access off and set Custom Rules to ask before it sends or buys anything. OpenAI announced dots on September 29, 2026 as always-on agents powered by GPT-6 Astra that operate within their own cloud computer and browser. Because dots launched today and are still rolling out, real-world operational reports are not in yet, but technical documentation outlines their security architecture.

Dots connect to over 4,000 apps through the plugin ecosystem and can work toward ongoing goals 24/7. Users can reach their primary dot in ChatGPT across desktop, web, and mobile, with support for connected messaging applications. While an agent can manage background responsibilities between conversations, granting access to personal email, corporate files, and calendar schedules introduces concrete operational risks.

The older dot icons in the ChatGPT interface are unrelated to these agents, as explained in our guide to ChatGPT dot meaning. The new autonomous agents require users to evaluate permission boundaries, data training policies, and access controls before delegating tasks. Safe deployment depends on keeping local device access disabled and requiring manual confirmation for critical actions.


What a Dot Can Do Without Asking

Letting a ChatGPT dot act on your accounts is safe for standard operational workflows if you keep local computer access disabled, set Custom Rules to ask before sending messages or buying items, and maintain human review on consequential deliverables. Dots ship with built-in rules that determine when an agent can proceed independently and when it must pause for confirmation.

To modify these boundaries, users configure Custom Rules with four distinct behaviors: "Take action without asking", "Take action if pre-approved", "Ask before taking action", and "Hand off to you". Pre-approved actions represent steps that you explicitly requested within your immediate prompt. Rules cover what your dot can share, purchase, or access across connected tools.

OpenAI includes an automated review mechanism called Auto-review that checks proposed actions against your instructions, Custom Rules, and foundational safety requirements. When an action could affect external accounts or transmit sensitive data, Auto-review evaluates whether the operation requires approval or must be completed by a person. Certain sensitive tasks, such as changing a password, always stay with you and cannot be delegated to an agent.

When you are not actively chatting with your dot, it conducts proactive research across connected tools to identify tasks where it can assist. OpenAI restricts proactive research tools to read-only mode, meaning background scans cannot alter app content, send outbound messages, or manipulate browser sessions. Even with these constraints, OpenAI notes that dots can still make mistakes, including when following your rules, which makes continuous oversight necessary.

Disconnecting an app does not delete what your dot learned from it; only a Reset does.

OpenAI Dots Safety Architecture and Cloud Isolation

OpenAI dots safety relies on a cloud computer architecture that keeps the agent execution environment isolated from your personal hardware. Each dot operates on its own dedicated cloud computer and uses its own cloud browser, preventing automated browsing sessions from touching local device files by default. You can inspect your dot by opening its computer view on desktop, while mobile sessions open the remote environment directly under your control.

Connecting a dot to local machine resources is optional and starts turned off. To enable local computer access, a user must open the ChatGPT desktop app on that specific computer and confirm an explicit prompt to allow access. Choosing "Revoke access" stops local access and leaves the dot on its own cloud computer where it cannot reach local files, local skills, or local browser sessions.

For authenticating into supported websites, dots can use saved passwords without exposing raw credentials to the underlying GPT-6 Astra model. OpenAI maintains security safeguards designed to intercept malicious prompt instructions and monitor for harmful execution patterns. If internal monitoring detects a safety concern during an ongoing task, OpenAI can pause or stop the dot's work.


Data Training Policies and Workspace Privacy

OpenAI does not use data or content from ChatGPT Business, Enterprise, or Edu workspaces to train its foundation models by default. For individual subscribers using Pro plans, data controls allow users to choose whether conversation logs and dot task artifacts contribute to model improvement.

Specific training exclusions also apply to background agent operations across all subscription tiers. OpenAI does not train directly on proactive research discoveries or the private notes that a dot writes to itself. Data gathered during background research may only influence model training if that information is subsequently incorporated into an eligible, training-permitted user conversation or task.

Administrative teams evaluating workspace privacy should review account settings before connecting organizational data sources. While institutional agreements offer default training protections, the broad visibility that dots maintain across connected cloud tools means internal privacy policies must dictate which accounts users connect.


Persistent Memories and Residual Operational Risks

Disconnecting an external integration from your dot does not delete the information that the agent previously collected from that service. A dot receives memories from ChatGPT conversations and continuously generates new memories from connected applications. To remove previously ingested application data or wipe the agent's memory bank, you must open the dot profile menu and select the Reset option, which permanently deletes the dot, its saved memories, chat history, and scheduled tasks.

Mobile messaging channels introduce secondary security considerations that differ from the main ChatGPT application. OpenAI provides a texting integration as a limited beta through a third-party provider for Pro subscribers located in the US, excluding Business and Enterprise workspaces. OpenAI advises caution when sharing sensitive information by text.

Technical safeguards do not eliminate the risk of logical execution errors. As OpenAI stated in the official announcement, dots can still make mistakes, meaning users must review consequential deliverables before acting on them. TechCrunch reported on the agent's approachable persona, but operators must treat dots as autonomous software capable of misinterpreting complex instructions.


Recommended Configuration Checklist for New Deployments

Establishing strict permission boundaries during the first month after launch limits what your dot can do on its own while you see how it handles requests. OpenAI published operational details in their getting started with your dot documentation, outlining how to restrict tool access and manage scheduled operations. Implementing conservative controls early allows you to observe how the agent interprets complex requests before granting broader autonomy.

  • Leave local computer access turned off unless a specific workflow requires local desktop tools.
  • Configure Custom Rules to require explicit approval before your dot shares data, makes purchases, or contacts outside parties.
  • Connect only the apps a first task needs, and review each app's permissions before connecting it.
  • Audit scheduled tasks under the profile view to verify recurring checks and execution schedules.
  • Review activity feeds regularly using Activity View to inspect work in progress and redirect tasks when necessary.
  • Execute a complete Reset from the settings menu if you need to wipe ingested data after disconnecting an integration.

Account Permissions and OpenAI Dots Safety Controls for Teams

Enterprise administrators maintain centralized governance over agent access across their organizational workspaces. On ChatGPT Enterprise, Edu, and Healthcare plans, dot access is disabled by default, requiring an administrator to explicitly enable the beta before employees can create agents. Organizations seeking dedicated institutional agents can evaluate specialist dots, which operate with unique digital identities, dedicated credentials, IT-provisioned hardware, and deep connections to corporate systems of record.

OpenAI is working with Microsoft to integrate specialist dot governance into Microsoft Agent 365, aligning administrative controls with enterprise security infrastructure. Teams deploying ChatGPT Business can access dots through Business Premium seats, priced at $125 per user per month, or $100 per user per month billed annually, while Standard seats cost $25 per user per month, or $20 per user per month billed annually. Because seat structures and rates may change, verify current figures on the official ChatGPT pricing page.

At Layer3Labs, we help operators review automated workflows, and we evaluate how agent permissions interface with corporate access policies. Teams rolling out multi-app agents often discover that existing permission roles in SaaS tools were set up for people, so they review agent access before connecting core systems. You can explore deployment architectures in our guide to ChatGPT dots for business or request an AI security audit to assess your organization's exposure.


Cloud Isolation vs Self-Hosted Agent Security

Comparing cloud-hosted dots to self-hosted tools highlights different operational trade-offs for technical teams. Each dot runs on its own cloud computer managed by OpenAI, while self-hosted agents such as OpenClaw run on hardware you manage. You can evaluate the technical trade-offs between managed cloud agents and local runtimes in our analysis of is OpenClaw safe for business.

This managed cloud approach is not suitable for organizations with air-gapped data residency mandates that prohibit third-party cloud execution or continuous external model calls. Teams with absolute on-premises compliance rules should deploy private, locally hosted model instances rather than connecting cloud-based dots.

Our verdict would flip if OpenAI eliminated granular Custom Rules or removed the ability to reset persistent agent memories across connected tools. Until real-world deployment data emerges over the coming months, begin by auditing connected integrations and testing custom rules before you give your dot sensitive work.

Frequently Asked Questions

  • No. OpenAI built-in safety rules stipulate that sensitive tasks, including changing a password, always stay with you and cannot be handled by a dot. For website authentication, dots can log in using saved passwords without exposing those credentials to the model.
  • OpenAI does not use data from ChatGPT Business, Enterprise, or Edu workspaces to train its models by default. On personal plans, you can control whether your dot's conversations and work are used. Furthermore, OpenAI does not train directly on proactive research scans or internal agent notes.
  • Only if you explicitly allow it. Local computer access starts turned off and requires you to open the ChatGPT desktop app and confirm access. You can revoke local access at any time, returning the dot to its isolated cloud computer and cloud browser.
  • Disconnecting an app stops future data collection, but it does not delete information the dot already obtained. To remove previously collected application data and saved memories, you must reset the dot through its profile menu, which deletes all memories, conversations, and scheduled tasks.
  • OpenAI has not published whether the built-in rules let a dot send email without asking. Set a Custom Rule to "Ask before taking action" or "Hand off to you" for sending, and your dot will ask first.

Audit Your Agent Security Boundaries

Book a consultation. We review your SaaS permissions, evaluate automated agent risks, and help configure safe approval workflows.

Book a Consultation