
You saw the headlines about OpenAI dots, agents that keep working in the background, and now you are wondering what one would actually do for your business. Maybe you have a pile of follow-ups, a calendar that never lines up, or an inbox you sort at 10 p.m. The questions that matter are simple. Does your ChatGPT plan include dots, what would it need to see, and is it safe to let something run all day? OpenAI announced dots on September 29, 2026, and its own pages answer most of that. This post walks through who can get one today, what a dot can reach, the controls you keep, and one low-risk task to try first. You can check your own eligibility in about ten minutes, and you do not have to connect anything sensitive to find out.
Key Takeaways
OpenAI says the first dot is included with Pro and Business Premium, and Enterprise, Edu and Healthcare get a beta when an administrator turns it on.
Pro access excludes the European Economic Area, Switzerland and the United Kingdom at rollout, while Business Premium is available across supported regions.
It works from its own cloud computer and browser plus the apps you link, and local computer access is optional.
You can redirect, pause, stop or reset a dot, set Custom Rules, and keep password changes and money transfers in your own hands.
A morning summary or draft follow-ups that need your approval give you a real test with little to lose.
What is OpenAI dots, and can you get one today?
A dot is what OpenAI calls an "always-on agent." It is powered by GPT-6 Astra and has its own cloud computer and browser, connected apps, persistent memory of its work, recurring tasks, and the ability to hand pieces of work to subagents. You reach it through ChatGPT, Slack and Teams. In plain terms, it can keep working on an approved job after you close the laptop, and it remembers what it has been doing.
Access depends on your plan and where you are. OpenAI says the first dot is included at no extra cost with Pro and Business Premium. Pro access excludes the European Economic Area, Switzerland and the United Kingdom at rollout. Business Premium is available across supported regions. Enterprise, Edu and Healthcare users can try a beta once an administrator enables it. If you are deciding on the Pro plan itself, our post on what ChatGPT Pro 500 gets a small business covers that side.
OpenAI says the first month includes extended limits. Check the usage shown in your own account before you plan around a number, because rollout can reach accounts at different times, even inside an eligible plan.

What can a dot reach, so you know what you are handing over?
A dot works from its own cloud computer and browser, plus the apps you connect through ChatGPT's app controls. OpenAI names Google Calendar, Google Drive, Docs, Sheets, Slides, GitHub, Slack, Microsoft Teams and more than 4,000 apps through its plugin ecosystem. Nothing is connected until you connect it, and each app has its own permissions.
You can also choose to connect a local computer, files, a browser, a camera, a microphone or a screen. Those need explicit setup, so a dot does not start with your laptop. Its cloud computer is separate from yours unless you link them.
| Area | What OpenAI says |
|---|---|
| Connected apps | Only the apps you connect, with permissions you approve |
| Local computer, camera, microphone, screen | Optional, and only after explicit setup |
| Proactive research | Limited to read-only tools; it cannot directly send messages, change app content or control a browser or computer |
| Password changes and money transfers | Stay under your control |
| Some sign-in steps | Stay under your control |
| Riskier actions | Run only under Custom Rules, approvals or your takeover |
Sign-in flows are designed so credentials go into a secure login form rather than being exposed to the model. That helps, and it does not replace choosing carefully which accounts to link.
How do you keep control of a dot that runs all day?
"Always-on" means a dot can continue approved work, run scheduled tasks and research in the background. It does not mean every action happens unsupervised. OpenAI gives you several ways to stay in charge.
- Activity View: It shows ongoing and delegated work, so you can see what the dot is doing.
- Redirect, pause, stop or reset: You can change course or shut a dot down at any time.
- Custom Rules: You can allow, block or require approval for supported actions.
- Specific approvals: Approval for one message does not give the dot open permission to contact people later.
- Its own computer, open to inspection: You can open your dot's computer and look at its work.
OpenAI also says dots can make mistakes and that consequential work should always be reviewed. Its privacy, security and safety FAQ explains that prompt injection, where text in a website, email or document tries to redirect an agent into sharing private information, is reduced by protections but not eliminated. That is the reason to give a dot the smallest set of accounts that gets one job done.

What happens to your business data?
For Business, Enterprise and Edu workspaces, OpenAI says data is not used to train models by default. On personal plans, the "Improve the model for everyone" setting controls whether dot conversations and work may be used for model improvement. OpenAI says it does not train directly on proactive research or a dot's private notes, although information carried from that research into an eligible conversation or task may be used depending on your settings.
A dot keeps what it learns from conversations and plugins for as long as the dot exists. Deleting the dot deletes its own stored memory, but files, conversations, Codex threads and ChatGPT memories stored elsewhere need to be managed separately. OpenAI encrypts content in transit and at rest, and says human review can happen in limited safety, support, legal, security or service-operation cases.
If you run a team workspace, OpenAI's guide to managing dots in workspaces covers the administrator side. For the general standards behind least-privilege access and human oversight, NIST's AI risk management guidance is a plain reference, and the FTC's business guidance reminds companies to keep reasonable security for customer information.
What can you check in ten minutes before you try it?
You can settle most of the decision before connecting a single account. Work through these in order.
- Look for dots: Open ChatGPT on the desktop web or the desktop app and see whether dots appears. Confirm your plan and country against the list above.
- List the accounts you would connect: Think of a business Gmail, a calendar, a Drive folder, Slack or Teams.
- Sort them by who owns the login: Note whether each one is a shared business login, an individual employee account or a personal account. Avoid starting with a personal account that mixes private and business information.
- Pick one repetitive, low-stakes task: A daily internal summary is a good candidate.
- Write the boundaries down: Read only, no outside messages, no purchases, no account changes, ask before anything else.
If you would rather have someone else make those calls, our AI consulting work covers exactly that kind of account and permission review.

Which first task gives you a real test with little to lose?
OpenAI's own examples include reviewing a calendar, researching a topic, preparing follow-ups, monitoring customer feedback, drafting content, updating documents and preparing invoices for approval. For a small business, several of those fit a narrow, reviewable pattern.
| Good first tasks | Keep manual or approval-only |
|---|---|
| Inbox triage summary | Payments and money transfers |
| Meeting preparation from your calendar | Password changes and account recovery |
| Recurring competitor or industry research | Permanent deletion |
| Draft follow-ups you approve before sending | Customer promises and legal commitments |
| Internal status summaries | Refunds and pricing changes |
| Calendar conflict report | Sending sensitive information |
Start with read-only or draft-only work. Judge it on a few things: did it use the right source, was the output accurate, and how long did your review take? Measure your own time before and after, since your tasks are what count. If the review takes as long as doing the task, the task was the wrong one.
Plan for the usual small-business failures too. Vague instructions send a dot after the wrong goal. Too much access, such as a personal mailbox when one shared folder would do, widens the risk. Unclear approval rules can lead to a message going out early. Each of those is fixed with a tighter instruction, narrower access or a firmer rule, and none of them needs a big project.

When can you skip dots for now?
You may not need a dot yet. If the task is rare, poorly defined, highly sensitive or already handled quickly by a person or a tool you trust, an always-on agent adds setup without much return. A simple rule in your email program or a plain scheduled report can be the better answer. A dot does not replace clean records, sensible access, or a person who is accountable for the result.
Because the first dot is included with an eligible plan, you can also try one low-risk task without buying anything extra and simply turn it off if it does not earn its place.
Are you ready to try a dot?
Pick an answer to begin.
1. Which plans get the first dot included, according to OpenAI?
2. A dot runs a background research task. What can it do directly?
3. Which is the best first task?
Frequently Asked Questions About openai dots
What are OpenAI dots?
They are always-on agents in ChatGPT that use their own cloud computer and browser, your connected apps and ongoing memory to keep approved work moving, including recurring tasks.
Which plans include dots?
OpenAI says the first dot is included with Pro and Business Premium. Enterprise, Edu and Healthcare users can try a beta when an administrator enables it. Pro access excludes the EEA, Switzerland and the UK at rollout.
Can a dot read my email and files?
Only through the apps and permissions you grant. Nothing is connected by default, and local computer access needs explicit setup.
Can it send messages without asking me?
Background research is read-only and cannot directly send messages or change content. Other actions can run under Custom Rules or approvals, and OpenAI says approval for one message does not cover later ones.
How do I stop a dot?
You can redirect it, tell it to stop, pause it or reset it, and Activity View shows what it is working on.
Does my business data train OpenAI models?
OpenAI says data from Business, Enterprise and Edu workspaces is not used for training by default. On personal plans, the "Improve the model for everyone" setting controls it.
Moving Forward
OpenAI dots are always-on agents that work through their own cloud computer and the apps you connect. The first dot is included with Pro and Business Premium, Pro excludes the EEA, Switzerland and the UK at rollout, and Enterprise, Edu and Healthcare get an administrator-enabled beta. You keep the controls: Activity View, pause and stop, Custom Rules, and approvals for consequential actions.
The safest way to learn what a dot is worth is a small test. Check your plan, connect one business-owned account, give it a read-only or draft-only job, and review the output before anything goes out. A narrow job with clear boundaries is easier to trust and easier to measure than a broad one.
If you want help choosing that first job, separating business accounts from personal ones and setting approval rules, Web Leveling can set it up with you, and our AI automation work covers exactly that. Contact Web Leveling about a first dot workflow and we will tell you plainly whether it is worth doing now. We work with small and medium businesses across the country and overseas.
Terms
Words used in this post
Tap a term to see what it means.
Dot. OpenAI's name for an always-on agent that keeps approved work going in the background.
Always-on agent. An AI assistant with its own cloud computer that can run tasks and recurring jobs without you present.
Activity View. A view of the work a dot is doing and has delegated.
Custom Rules. Settings that allow, block or require approval for supported actions.
Prompt injection. Text in a website, email or document that tries to redirect an agent into sharing private information.
Least privilege. Giving a tool only the access it needs for one job.




