Skip to content

Product1 publisher3 min readPublished

OpenAI leaves the Dots beta switch with enterprise workspace admins

OpenAI is letting enterprise workspace admins decide whether staff get Dots, its always-on ChatGPT agents that can connect to more than 4,000 apps. Whoever turns on the beta approves software that keeps working while nobody watches, under permission rules each employee writes for their own Dot.

The Product Desk · Product desk

What happened

  • ChatGPT Pro and Business Premium subscribers in eligible markets are in the first rollout wave for Dots.
  • OpenAI says wider access is coming "soon" but has set no date for Plus, Go or Free users.
  • Dots run on GPT-6 Astra and can work on several projects at once, learn from feedback and keep going around the clock.
  • Staff can reach their Dot through ChatGPT, Slack or Teams.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Admins on Enterprise, Edu and Healthcare plans now own a yes-or-no call on an agent that keeps working after staff log off, and they are the ones asked about it when a Dot misfires.
  • exposure Because permissions are written user by user, a workspace that enables Dots ends up with one permission policy per Dot user, and the published description gives the admin no central way to review them.
  • constraint Unprompted work is capped at reading, so the payoff OpenAI demonstrates, a Dot catching a missed invoice, still ends with a person approving the send.

An early tester's Dot noticed he had forgotten to invoice a publication. It drew up the invoice and sent it once he approved, according to Tom's Guide [9]. OpenAI calls this "proactive research": a Dot going looking for useful work that nobody prompted [8].

OpenAI is pitching a colleague that finds work. For anyone on an Enterprise, Edu or Healthcare plan, what actually happens on Monday is a workspace setting. Staff get the beta only if an administrator enables it [3].

The setting covers a lot of reach. Each Dot has its own cloud computer and browser and keeps going after the user closes ChatGPT [1]. OpenAI says it can connect to more than 4,000 apps through its plugin ecosystem [6].

Tom's Guide describes the guardrails in layers. While a Dot is hunting for work on its own, its connected-app tools are read-only. It cannot send messages, edit content inside an app or control the browser or computer [10]. Actions that could affect accounts or share information go through auto-review against the user's instructions and OpenAI's safety requirements [12]. Some sensitive jobs, such as changing a password, always stay with the person [13].

The remaining settings belong to the user. Each person picks which apps their Dot can reach and writes Custom Rules that sort its actions into three groups: ones it takes alone, ones that need approval and ones that are blocked [11]. Tom's Guide does not describe any admin control beyond the workspace switch. On that record, an admin who enables the beta hands permission design to each employee [1].

The model underneath is good but not finished. OpenAI's testing found GPT-6 Astra considerably better than previous models at staying within its authorised scope, but not perfect, Tom's Guide reports [14]. The reviewer's concern is drift. Permission granted for one task may not be wanted for the next, and the boundaries get harder to track as an agent juggles more jobs [15].

I would enable the beta for a small group, chosen by what their connected apps can do when an action goes wrong. The tradeoff is that a careful pilot shows the least of what OpenAI is selling. A Dot confined to low-stakes apps finds low-stakes work, and its unprompted work stops at reading anyway [10].

Two axes sort the teams. The first is whether a wrong action in a team's apps reaches someone outside the company, as a sent message or an invoice, or stays internal and reversible. The second is whether the team's Dots run one job or several, since scope gets harder to track as jobs pile up [15].

Teams whose mistakes stay internal and who run one job go first. Add the internal, multi-job teams next, once someone other than the author has read their Custom Rules. A team whose errors reach customers can still run a single job with approval required on every send, a setting Custom Rules allow [11]. Teams with outside exposure and many jobs wait until OpenAI publishes more on admin controls and scope testing.

What to watch

  • Whether OpenAI adds workspace-level controls that let admins set or review app access and Custom Rules for every Dot.
  • A date for Plus, Go and Free access, which OpenAI has so far described only as "soon".
  • Published figures on how often GPT-6 Astra strays outside its authorised scope in OpenAI's testing.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories