OpenAI's Dots run 24/7 with 4,000+ app connections. Here are the permission rules
OpenAI's always-on GPT-6 Astra agents work from their own cloud computers and can reach more than 4,000 apps. What holds them back is a read-only research mode, an automated check called auto-review, and rules the owner writes.
Idle Dots can read your apps but not write to them. Anything that touches an account has to clear auto-review first.
OpenAI launched Dots at DevDay on September 29: always-on agents powered by GPT-6 Astra, each working from "a cloud computer of its own," SiliconANGLE reported. Through OpenAI's plugins, a Dot can reach more than 4,000 apps, and owners talk to it through ChatGPT, Slack, or Teams.
A Dot learns its owner's preferences from feedback, SiliconANGLE reported, and works on their goals "24/7," according to MacRumors, which said texting is planned. One Dot is included with ChatGPT Pro and Business Premium, according to SiliconANGLE. OpenAI has not disclosed what additional Dots will cost. Enterprise, Edu, and Healthcare workspaces get a beta once an admin turns it on, The Next Web reported. Pro subscribers in the European Economic Area, Switzerland, and the UK are not included at launch.
An idle Dot can read your apps, not write to them
When nobody has given a Dot a task, it goes looking for ways to help. OpenAI calls this proactive research. During it, the agent's connections to the owner's apps are read-only, SiliconANGLE reported, "so it cannot send messages or change anything."
The Decoder adds that background mode uses only read-only tools, which "can't send messages, change content, or control a browser or computer." An Activity View shows that background work, and the owner can click "Take over" to step in.
Account actions go through auto-review and Custom Rules
Actions that could touch a user's accounts or share information must first clear a check called auto-review, according to SiliconANGLE. The Decoder describes it as an automated system that tests those actions against rules the user has defined before they run.
Those rules are called Custom Rules. Per The Decoder, they "let users allow individual actions, require approval for them, or ban them outright." The Next Web reported that some sensitive tasks, such as changing a password, always stay with the user, and that Dots sign in to supported sites with saved passwords without exposing them to the model.
Two more controls sit on top. A monitoring system can pause or stop an agent over a safety concern, SiliconANGLE reported. A Dot can also work directly on its owner's laptop, but only with permission, SiliconANGLE and The Decoder reported.
Specialist Dots get their own identity
OpenAI also previewed specialist Dots, which an employer provisions "with their own identity and credentials for a single defined job," per SiliconANGLE. The Decoder reported that companies can also give them computers supplied by IT. OpenAI is working with Microsoft to manage these agents through the governance and security controls in Agent 365, TechCrunch reported.
What the launch coverage leaves open
None of the six outlets we read said which actions auto-review lets through by default, or what the built-in rules are before an owner writes any. OpenAI itself tells users to review consequential work, because the agents "can still make mistakes," SiliconANGLE reported.
The launch also has recent context. On September 20, an OpenAI training agent used DNS lookups to get data out of a sandbox. OpenAI also shelved GPT-6.1 Astra over safety concerns on September 28, The Hacker News reported. Meta's rival agent, Muse, also runs on its own computer and asks for approval before sensitive actions, per The Decoder. A researcher found a zero-day in Muse 13 days after it shipped.
Why a build studio cares
Read-only proactive research is the right default, and it still leaves half the risk in place. A Dot connected to email and Slack reads untrusted text all day, and read access to 4,000 possible apps is half of what a leak needs. The write half is guarded by auto-review, an automated check, and a human only sits in the loop where an owner's Custom Rules say "require approval." So the rules are the security model, and most owners will write them after connecting apps, not before. When we map data flows for an agent pipeline, we would treat every connector a Dot holds as a read path to list, and a specialist Dot's credentials like a service account: one job, scoped access, rotated keys.
Next step: read OpenAI's announcement, Introducing dots, then The Decoder's write-up for the rule types. If you are about to connect a Dot to company email or Slack and want its read paths mapped before you write its Custom Rules, write to us at hello@gattyworks.com.