ai automation

OpenAI dots: who can get it and a safe first task

OpenAI dots are always-on ChatGPT agents. See which plans get one, what it can reach, the controls you keep and one low-risk first task for your business.

You saw the headlines about OpenAI dots, agents that keep working in the background, and now you are wondering what one would actually do for your business. Maybe you have a pile of follow-ups, a calendar that never lines up, or an inbox you sort at 10 p.m. The questions that matter are simple. Does your ChatGPT plan include dots, what would it need to see, and is it safe to let something run all day? OpenAI announced dots on September 29, 2026, and its own pages answer most of that. This post walks through who can get one today, what a dot can reach, the controls you keep, and one low-risk task to try first. You can check your own eligibility in about ten minutes, and you do not have to connect anything sensitive to find out.

Key Takeaways

Plan decides access

OpenAI says the first dot is included with Pro and Business Premium, and Enterprise, Edu and Healthcare get a beta when an administrator turns it on.

Region matters for Pro

Pro access excludes the European Economic Area, Switzerland and the United Kingdom at rollout, while Business Premium is available across supported regions.

A dot only reaches what you connect

It works from its own cloud computer and browser plus the apps you link, and local computer access is optional.

You keep the brakes

You can redirect, pause, stop or reset a dot, set Custom Rules, and keep password changes and money transfers in your own hands.

Start with draft-only work

A morning summary or draft follow-ups that need your approval give you a real test with little to lose.

What is OpenAI dots, and can you get one today?

A dot is what OpenAI calls an "always-on agent." It is powered by GPT-6 Astra and has its own cloud computer and browser, connected apps, persistent memory of its work, recurring tasks, and the ability to hand pieces of work to subagents. You reach it through ChatGPT, Slack and Teams. In plain terms, it can keep working on an approved job after you close the laptop, and it remembers what it has been doing.

Access depends on your plan and where you are. OpenAI says the first dot is included at no extra cost with Pro and Business Premium. Pro access excludes the European Economic Area, Switzerland and the United Kingdom at rollout. Business Premium is available across supported regions. Enterprise, Edu and Healthcare users can try a beta once an administrator enables it. If you are deciding on the Pro plan itself, our post on what ChatGPT Pro 500 gets a small business covers that side.

OpenAI says the first month includes extended limits. Check the usage shown in your own account before you plan around a number, because rollout can reach accounts at different times, even inside an eligible plan.

A closed laptop, a small stack of blank index cards and a brass desk clock on a worn wooden desk, photographed from above.
Check your plan and region first; the answer decides everything after it.

What can a dot reach, so you know what you are handing over?

A dot works from its own cloud computer and browser, plus the apps you connect through ChatGPT's app controls. OpenAI names Google Calendar, Google Drive, Docs, Sheets, Slides, GitHub, Slack, Microsoft Teams and more than 4,000 apps through its plugin ecosystem. Nothing is connected until you connect it, and each app has its own permissions.

You can also choose to connect a local computer, files, a browser, a camera, a microphone or a screen. Those need explicit setup, so a dot does not start with your laptop. Its cloud computer is separate from yours unless you link them.

What a dot can and cannot do on its own, per OpenAI
AreaWhat OpenAI says
Connected appsOnly the apps you connect, with permissions you approve
Local computer, camera, microphone, screenOptional, and only after explicit setup
Proactive researchLimited to read-only tools; it cannot directly send messages, change app content or control a browser or computer
Password changes and money transfersStay under your control
Some sign-in stepsStay under your control
Riskier actionsRun only under Custom Rules, approvals or your takeover
AreaConnected apps
What OpenAI saysOnly the apps you connect, with permissions you approve
AreaLocal computer, camera, microphone, screen
What OpenAI saysOptional, and only after explicit setup
AreaProactive research
What OpenAI saysLimited to read-only tools; it cannot directly send messages, change app content or control a browser or computer
AreaPassword changes and money transfers
What OpenAI saysStay under your control
AreaSome sign-in steps
What OpenAI saysStay under your control
AreaRiskier actions
What OpenAI saysRun only under Custom Rules, approvals or your takeover

Sign-in flows are designed so credentials go into a secure login form rather than being exposed to the model. That helps, and it does not replace choosing carefully which accounts to link.

How do you keep control of a dot that runs all day?

"Always-on" means a dot can continue approved work, run scheduled tasks and research in the background. It does not mean every action happens unsupervised. OpenAI gives you several ways to stay in charge.

  • Activity View: It shows ongoing and delegated work, so you can see what the dot is doing.
  • Redirect, pause, stop or reset: You can change course or shut a dot down at any time.
  • Custom Rules: You can allow, block or require approval for supported actions.
  • Specific approvals: Approval for one message does not give the dot open permission to contact people later.
  • Its own computer, open to inspection: You can open your dot's computer and look at its work.

OpenAI also says dots can make mistakes and that consequential work should always be reviewed. Its privacy, security and safety FAQ explains that prompt injection, where text in a website, email or document tries to redirect an agent into sharing private information, is reduced by protections but not eliminated. That is the reason to give a dot the smallest set of accounts that gets one job done.

A padlock, a brass key and a blank paper tag on a dark wooden tray.
Decide what a dot may touch before it touches anything.

What happens to your business data?

For Business, Enterprise and Edu workspaces, OpenAI says data is not used to train models by default. On personal plans, the "Improve the model for everyone" setting controls whether dot conversations and work may be used for model improvement. OpenAI says it does not train directly on proactive research or a dot's private notes, although information carried from that research into an eligible conversation or task may be used depending on your settings.

A dot keeps what it learns from conversations and plugins for as long as the dot exists. Deleting the dot deletes its own stored memory, but files, conversations, Codex threads and ChatGPT memories stored elsewhere need to be managed separately. OpenAI encrypts content in transit and at rest, and says human review can happen in limited safety, support, legal, security or service-operation cases.

If you run a team workspace, OpenAI's guide to managing dots in workspaces covers the administrator side. For the general standards behind least-privilege access and human oversight, NIST's AI risk management guidance is a plain reference, and the FTC's business guidance reminds companies to keep reasonable security for customer information.

What can you check in ten minutes before you try it?

You can settle most of the decision before connecting a single account. Work through these in order.

  1. Look for dots: Open ChatGPT on the desktop web or the desktop app and see whether dots appears. Confirm your plan and country against the list above.
  2. List the accounts you would connect: Think of a business Gmail, a calendar, a Drive folder, Slack or Teams.
  3. Sort them by who owns the login: Note whether each one is a shared business login, an individual employee account or a personal account. Avoid starting with a personal account that mixes private and business information.
  4. Pick one repetitive, low-stakes task: A daily internal summary is a good candidate.
  5. Write the boundaries down: Read only, no outside messages, no purchases, no account changes, ask before anything else.

If you would rather have someone else make those calls, our AI consulting work covers exactly that kind of account and permission review.

A single ruled notepad with blank lines beside a pencil and a small brass bell on a wooden table.
One narrow job, written down before anything is connected.

Which first task gives you a real test with little to lose?

OpenAI's own examples include reviewing a calendar, researching a topic, preparing follow-ups, monitoring customer feedback, drafting content, updating documents and preparing invoices for approval. For a small business, several of those fit a narrow, reviewable pattern.

Good first tasks and work that stays manual
Good first tasksKeep manual or approval-only
Inbox triage summaryPayments and money transfers
Meeting preparation from your calendarPassword changes and account recovery
Recurring competitor or industry researchPermanent deletion
Draft follow-ups you approve before sendingCustomer promises and legal commitments
Internal status summariesRefunds and pricing changes
Calendar conflict reportSending sensitive information
Good first tasksInbox triage summary
Keep manual or approval-onlyPayments and money transfers
Good first tasksMeeting preparation from your calendar
Keep manual or approval-onlyPassword changes and account recovery
Good first tasksRecurring competitor or industry research
Keep manual or approval-onlyPermanent deletion
Good first tasksDraft follow-ups you approve before sending
Keep manual or approval-onlyCustomer promises and legal commitments
Good first tasksInternal status summaries
Keep manual or approval-onlyRefunds and pricing changes
Good first tasksCalendar conflict report
Keep manual or approval-onlySending sensitive information

Start with read-only or draft-only work. Judge it on a few things: did it use the right source, was the output accurate, and how long did your review take? Measure your own time before and after, since your tasks are what count. If the review takes as long as doing the task, the task was the wrong one.

Plan for the usual small-business failures too. Vague instructions send a dot after the wrong goal. Too much access, such as a personal mailbox when one shared folder would do, widens the risk. Unclear approval rules can lead to a message going out early. Each of those is fixed with a tighter instruction, narrower access or a firmer rule, and none of them needs a big project.

A worn wooden inbox tray holding a few blank envelopes next to a closed notebook.
Sorting and drafting are safer first jobs than sending or paying.

When can you skip dots for now?

You may not need a dot yet. If the task is rare, poorly defined, highly sensitive or already handled quickly by a person or a tool you trust, an always-on agent adds setup without much return. A simple rule in your email program or a plain scheduled report can be the better answer. A dot does not replace clean records, sensible access, or a person who is accountable for the result.

Because the first dot is included with an eligible plan, you can also try one low-risk task without buying anything extra and simply turn it off if it does not earn its place.

Are you ready to try a dot?

Pick an answer to begin.

1. Which plans get the first dot included, according to OpenAI?

2. A dot runs a background research task. What can it do directly?

3. Which is the best first task?

Frequently Asked Questions About openai dots

What are OpenAI dots?

They are always-on agents in ChatGPT that use their own cloud computer and browser, your connected apps and ongoing memory to keep approved work moving, including recurring tasks.

Which plans include dots?

OpenAI says the first dot is included with Pro and Business Premium. Enterprise, Edu and Healthcare users can try a beta when an administrator enables it. Pro access excludes the EEA, Switzerland and the UK at rollout.

Can a dot read my email and files?

Only through the apps and permissions you grant. Nothing is connected by default, and local computer access needs explicit setup.

Can it send messages without asking me?

Background research is read-only and cannot directly send messages or change content. Other actions can run under Custom Rules or approvals, and OpenAI says approval for one message does not cover later ones.

How do I stop a dot?

You can redirect it, tell it to stop, pause it or reset it, and Activity View shows what it is working on.

Does my business data train OpenAI models?

OpenAI says data from Business, Enterprise and Edu workspaces is not used for training by default. On personal plans, the "Improve the model for everyone" setting controls it.

Moving Forward

OpenAI dots are always-on agents that work through their own cloud computer and the apps you connect. The first dot is included with Pro and Business Premium, Pro excludes the EEA, Switzerland and the UK at rollout, and Enterprise, Edu and Healthcare get an administrator-enabled beta. You keep the controls: Activity View, pause and stop, Custom Rules, and approvals for consequential actions.

The safest way to learn what a dot is worth is a small test. Check your plan, connect one business-owned account, give it a read-only or draft-only job, and review the output before anything goes out. A narrow job with clear boundaries is easier to trust and easier to measure than a broad one.

If you want help choosing that first job, separating business accounts from personal ones and setting approval rules, Web Leveling can set it up with you, and our AI automation work covers exactly that. Contact Web Leveling about a first dot workflow and we will tell you plainly whether it is worth doing now. We work with small and medium businesses across the country and overseas.

Terms

Words used in this post

Tap a term to see what it means.

Dot. OpenAI's name for an always-on agent that keeps approved work going in the background.

Always-on agent. An AI assistant with its own cloud computer that can run tasks and recurring jobs without you present.

Activity View. A view of the work a dot is doing and has delegated.

Custom Rules. Settings that allow, block or require approval for supported actions.

Prompt injection. Text in a website, email or document that tries to redirect an agent into sharing private information.

Least privilege. Giving a tool only the access it needs for one job.