Invest2 publishers2 min readPublished
Password changes by OpenAI's Dots agents wait on one user's sign-off
OpenAI's Dots agents, arriving in a business base of more than 35 million weekly users, must get a user's sign-off before changing a password or deleting data. Permissions are adjustable settings, so each team deploying an always-on Dot sets its own limits.
The Investor · Invest desk

What happened
- OpenAI launched Dots on September 29 on its GPT-6 Astra model, built to keep working continuously across Slack, Microsoft Teams and other workplace platforms.
- Each Dot has its own cloud computer, learns from user feedback over time and works toward its owner's goals around the clock, Yahoo Finance reported.
- Holly Li of OpenAI's product team said staff already bring their Dots into group chats, where the agents work with colleagues and with other Dots.
- Meta released its rival Muse agent earlier in September, and it quickly racked up millions of downloads.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Every team adopting Dots has to choose which user permissions to grant and who may approve a sensitive action, because the controls on offer are settings the customer adjusts.
- exposure When one person's Dot acts on a request relayed by a colleague's Dot, the stated check is one user's sign-off, so a single click can approve work someone else started.
- constraint An agent pitched on working 24/7 still pauses at each password change or deletion until its owner answers, so overnight work stops at the first sensitive step.
"I get to decide what needs my attention and what my Dot can take care of," Holly Li, a member of OpenAI's product team, said at DevDay [9][16]. The required sign-off on password changes and deletions [2] gives the riskiest version of that choice to the same person. The other protections OpenAI and Meta point to are all adjustable: custom data controls, user permissions that can be changed, and settings that keep enterprise usage data from being retained [3].
A per-user check is harder to reason about once the agents deal with each other. "By giving Dots their own identity, they become extensions of our team," Li said [10]. In her demo she forwarded a colleague's Slack request to her own Dot, Dottie [16]. The sources do not say whether a consent prompt shows the user who started a relayed request. Cryptobriefing linked the industry's focus on trust to earlier incidents in which AI models interacted in ways people did not expect [13].
OpenAI reported more than 35 million weekly users across Codex and ChatGPT Work in late September [4], against more than 1.2 billion weekly users of consumer ChatGPT [5]. That puts the business base at about 2.9% of the consumer one [1]. Yahoo Finance put OpenAI's annualized revenue near $70 billion [7] and called a Dot that can reach 4,000 apps through ChatGPT a direct challenge to Meta's Muse [8][17].
Teams could grant wide permissions and treat the prompt as the whole control. They could narrow permissions until Dots mostly sort threads, the job Li showed when she said, "Now I can forward the thread to Dottie. I can just delegate." [15] Or individual users could switch agents on before any IT policy exists. Muse's early download count [11] is the evidence for that third path.
In my view the second outcome is the likeliest at companies with a security team, because the customer sets every control on offer [3] and a narrow grant is the cautious setting. On that path, the growth OpenAI can show inside its 35 million business users [4] comes from thread work, the lowest-risk task an always-on agent [6] can be given. I would be wrong if Dots start changing passwords and deleting data at scale in enterprise accounts where the user prompt is the only gate [2].
What to watch
- Whether OpenAI adds team- or administrator-level approval rules for sensitive Dot actions on top of the per-user sign-off.
- OpenAI's next weekly-user count for Codex and ChatGPT Work, measured against the 35 million it reported in late September.
- Whether regulators set formal limits on what AI agents may do without asking first.