Build2 publishers3 min readPublished
OpenAI gives each always-on Dots agent its own cloud computer
OpenAI is rolling out Dots, persistent GPT-6 Astra agents reachable from ChatGPT, Slack and Microsoft Teams, to Pro and Business Premium users. Before connecting one, a team has to settle what it may read unattended and which of its actions need approval.
The Engineer · Build desk

What happened
- Enterprise, Edu and Healthcare workspaces can enable the dots beta through an administrator.
- OpenAI also previewed specialist dots for organizational roles, each with its own identity, credentials and system access.
- The first dot comes with no added subscription charge, but its Work and Codex tasks count against the usual plan allowance.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Connector choices are data-access decisions for whoever owns the workspace: each connector a team attaches widens what a dot reads on its own initiative.
- exposure Endpoint policy has to be part of any dots rollout, because the laptop option lets a cloud-hosted agent reach a local machine.
- precedent Specialist dots holding their own credentials under Microsoft's Agent 365 controls make it likely that enterprises provision and revoke agents as identities of their own, next to staff accounts.
- cost Every Work or Codex task a dot performs spends plan allowance. A busy agent draws on the same allowance as its owner's own work.
In OpenAI's description, as RuntimeWire reported it, a dot runs at two privilege levels. Its background loop, which OpenAI calls proactive research, uses connected tools in read-only mode [6]. Anything that changes state follows permissions and approval rules [6]. For an agent with a cloud computer of its own [2], I think that is the right default, because the part that runs unattended cannot write.
The keynote demo shows where the line gets tested. OpenAI showed a dot delegating Slack requests, investigating bugs and preparing pull requests [5]. Bug investigation sits on the read side. A pull request is a write to a repository. That puts it under the approval rules, and a build team has to decide who approves it and in which tool.
Read-only access still moves data. A dot carries context between conversations and across several ongoing projects [2]. Its owner can reach it from ChatGPT, Slack or a Microsoft Teams voice call [3]. What it read in the background can come back in any of those channels. "Proactive research" is a polite name for an agent reading connected tools on its own initiative. The optional laptop connection, granted with permission, extends that reach from the cloud computer to a local machine [4].
OpenAI previewed specialist dots for organizational responsibilities, each with its own identity, credentials and system access [10]. An agent that holds its own credentials can be scoped and revoked without touching an employee's account. Initial enterprise pilots cover defined workflows [11]. OpenAI is working with Microsoft to integrate specialist dots with Agent 365's governance and security controls [12].
According to OpenAI's launch materials, dots are rolling out to Pro and Business Premium users in eligible markets [7]. Enterprise, Edu and Healthcare workspaces enable the beta through an administrator [8]. The rundown does not say whether Business Premium gets a comparable admin switch, or what the approval rules are by default.
The first dot comes with the subscription at no extra charge, but its Work and Codex tasks draw on the plan's usual allowance [9]. If background work counts as those tasks, an always-on agent spends allowance on its own schedule. Allowance terms also changed at DevDay on September 29th [1]. New subscribers to the reopened $200 Pro tier who are not grandfathered get a smaller allowance than the previous offering. Existing subscribers keep the old allowance only through October 29, 2026 [14]. Pro 500 costs $500 a month and offers an allowance OpenAI describes as 25 times Plus usage [13].
Teams building their own agents get a similar division of labor in the Agents API. OpenAI runs sessions, orchestration, context compaction and recovery for a managed Codex harness, and developers supply the tools [15]. In that design, the permission boundary is the tool list the developer writes.
What to watch
- OpenAI documentation of the default approval rules for dots, and whether Business Premium administrators can restrict or disable them.
- Whether the Agent 365 integration extends beyond the specialist-dot pilots and their defined workflows.
- Whether proactive research stays read-only as OpenAI adds connectors and the promised texting channel.