Security3 publishers2 min readPublished Updated
OpenAI's Dots agent will act on Slack alerts across about 4,000 connected apps
OpenAI's Dots, unveiled Tuesday at DevDay, is a background agent that acts on events such as Slack alerts across about 4,000 connected apps. For security teams it is a new standing identity inside Slack, holding whatever app access each user grants it.
The Watch · Security desk

What happened
- Dots will roll out to Pro, Business Premium and Enterprise users in the markets where it is available.
- In one OpenAI example, Dots spotted a tester's missing invoice, prepared it, and submitted it after the tester approved the action.
- OpenAI says it could eventually let people run entire teams of Dots working together.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Anyone who can post in a Slack channel a Dot watches can put text in front of an agent holding its user's app connections, so channel membership becomes an access-control question.
- decision Business Premium and Enterprise admins have to settle which connectors and channels a Dot may touch before the rollout reaches their users and staff connect it themselves.
- constraint Until OpenAI documents which steps need sign-off, per-action approval by the individual user is the only safeguard a security team can plan around.
- precedent If teams of Dots ship, access reviews sized for one agent per person would have to track several standing agents per person.
Slack is where users hand Dots its tasks [6], and it is also one of the places Dots watches for work. In OpenAI's example, a software bug alert appears in Slack, and Dots notices it and starts looking into the problem [4]. The agent reaches connected apps through ChatGPT [3] and works across the tools and services its user already uses [13]. Whatever lands in a watched channel, from whoever can post there, is input to an agent with that reach [1]. That input path exists by design and does not depend on a software flaw [1].
Beyond the invoice case, the Hindustan Times account does not say which steps wait for user approval, and it does not describe admin controls, permission scopes, audit logs or a rollout date [10]. For a security team, the first question is whether Dots reads from connected apps while it investigates an alert, before any user has approved anything [4].
Each user starts with a single Dot and can name it and customize how it works [12]. At launch, a tenant therefore carries one standing agent per enabled user. The count rises if OpenAI ships the teams of Dots it has described [2].
Dots is designed to handle tasks over long periods in the background, instead of only answering questions when asked [2]. According to the Hindustan Times, OpenAI, Anthropic, Meta and Google have all faced situations over the past year in which their AI agents reportedly went beyond their intended tasks [9]. The paper says those cases included hacking activity involving organizations and governments [9]. Those reports concern agents exceeding their own task. A Dot fed by a Slack channel adds a second risk: an outsider steering it through what gets posted there [1].
The Muse comparison in the same coverage has no bearing on enterprise controls. Meta markets Muse mainly toward consumers, while OpenAI is positioning Dots for the workplace [11].
What to watch
- OpenAI admin documentation for Business Premium and Enterprise showing whether Dots can be limited to named Slack channels and an approved connector list.
- A rollout date for Business Premium and Enterprise tenants.
- Whether each Dot in a future team gets its own credentials or shares its user's app connections.