Build5 publishers3 min readPublished
OpenAI confines its always-on Dots agents to read-only tools while users are away
OpenAI's Dots agents run nonstop on their own cloud computers, with only read-only tools for background work across more than 4,000 connected apps. Acting on what they find goes through rules each user sets, so permission design is the first job for any company that deploys one.
The Engineer · Build desk

What happened
- Custom Rules let each user allow an action, require approval for it, or block it, while sensitive tasks such as changing a password always stay with the user.
- Users reach a Dot through ChatGPT, Slack and Microsoft Teams, and the agent keeps its context across all three channels.
- OpenAI also previewed specialist Dots that an organization provisions with their own identity, credentials, IT-provisioned hardware and access to systems of record.
- Meta says its Muse agent, launched three weeks earlier, also runs on its own computer, works in the background and asks before sensitive actions.
- Each user gets one Dot at launch, and Pro subscribers in Europe cannot use the feature for now.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Because users set Custom Rules themselves, a company rolling out Dots has to decide whether employees choose their own allow and approval lists or IT sets them centrally.
- exposure Every Slack or Teams message a background Dot reads becomes model input, so a planted instruction reaches the agent without anyone assigning it a task, and only the safeguards and auto-review sit between that text and an action.
- capability Specialist Dots with their own identity let an organization scope an agent's access to one workflow instead of stretching one employee's permissions to cover it.
- precedent With Muse and Dots shipping the same own-computer, approve-before-sensitive-action design three weeks apart, buyers can hold agent vendors to a common set of control points.
I think the read-only limit is the best-built control in the design, because it works by removing tools. When nobody is working with a Dot, it looks through connected apps for ways to help, a mode OpenAI calls proactive research [4]. In that mode it holds only tools that cannot send messages, change app content, or control a browser or computer [5].
Active work runs on a different kind of control. Any action that touches accounts or shares information passes an auto-review step. That step checks the action against the user's instructions, OpenAI's safety requirements and the user's Custom Rules [6]. This is a judgement call. Something has to decide whether a given call counts as sharing information, and the approval scheme is only as good as that decision. OpenAI did not publish how auto-review makes it or how often it misses.
The two modes also share state. A Dot writes notes to itself [10], and background research exists to find work the Dot will later carry out. Text read in the read-only phase therefore shapes what the Dot proposes once it can act. The New Stack described malicious instructions as a real concern for an agent reading content from thousands of connected apps [8]. OpenAI says safeguards are meant to block such instructions, and a monitoring system can pause or stop a Dot if safety concerns come up [9].
OpenAI's invoice example shows the intended split between the modes. For an early tester, a Dot spotted a forgotten invoice, prepared it, and sent it once the tester approved [11].
Credentials are kept away from the model. On supported websites a Dot can sign in with saved passwords the model never sees [12]. The user's laptop stays outside the Dot's environment unless the user connects it [13]. An Activity View lists what the Dot is doing, background tasks included [14]. OpenAI still says Dots can make mistakes and recommends double-checking any result with real consequences [15].
A personal Dot gets a name and a cartoon avatar [16]. Neither shows up in an access review. The specialist version, with its own identity and credentials, is the one built for IT [17]. OpenAI has tested it internally in procurement, invoice processing, email marketing, customer support and commercial contracting [18]. External deployments will start as enterprise pilots, in which OpenAI engineers work with each customer to define a Dot's responsibilities, tool access and review points [19].
Training policy depends on the plan. OpenAI says it does not use Business, Enterprise or Edu workspace content to improve its models by default, and personal-plan users choose for themselves [20]. It does not train directly on proactive research or on a Dot's notes, though that material may be used if it informs an eligible conversation or task, depending on settings [21].
Dots run on GPT-6 Astra [22]. According to The Decoder, OpenAI is holding back the top-end GPT-6.1 Astra over safety problems [23].
What to watch
- Whether OpenAI publishes how auto-review classifies an action as account-touching or information-sharing, and any miss rate, before enterprise pilots start.
- What central controls over Custom Rules Business and Enterprise customers get, beyond the unspecified extra options The Decoder reports.
- Whether Dots move from GPT-6 Astra to GPT-6.1 Astra once OpenAI resolves the safety problems holding that model back.