OpenAI Dots: always-on agents, read-only until you approve
OpenAI Dots run 24/7 on their own cloud computer with 4,000+ app connections. The approval rules you set are the whole product. Here's how to set them.
OpenAI launched Dots at DevDay today: always-on AI agents that live inside ChatGPT, run on their own cloud computer, and keep working after you close the tab. That makes OpenAI Dots the first mainstream background agent a small team can switch on from a plan it already pays for. The interesting part isn't that it runs 24/7. It's where OpenAI drew the line on what it can do without asking.
What actually happened
Per 9to5Google, each dot runs on GPT-6 Astra with its own cloud computer and reaches more than 4,000 apps through ChatGPT's plugin ecosystem. You assign it ongoing work, and it runs around the clock. You talk to it in ChatGPT, Slack, Microsoft Teams, or by voice call.
The rollout is narrow. Pro and Business Premium users get one dot included. Enterprise workspaces get a beta once an admin turns it on. OpenAI says you'll be able to add more dots later but has not published a price. As we covered in our Pro 500 post, Dots are not available at launch to Pro users in the EEA, Switzerland, or the UK.
The control model has two modes. When a dot does "proactive research" in the background, its app connections are read-only. When it runs a task, you set custom rules so it either acts alone or waits for approval. The Associated Press reported that Sam Altman skipped the security questions around agents in his keynote, and only said in the Q&A that OpenAI is spending more on agent safety and monitoring.
Why OpenAI Dots matter for your business
A dot with read access to your inbox, CRM, and Shopify admin is a 24/7 analyst. It can find the unpaid invoice, the stalled deal, and the SKU about to stock out. That's real value, and read-only is a sane default for it.
The risk starts when you change the default. The approval rules are the product. "Act on its own" is fine for drafting a summary. It is not fine for sending a customer email, issuing a refund, or editing a price. We'd write the rule set before you connect anything:
- Read freely: reports, inboxes, order history.
- Draft, then ask: customer replies, supplier emails, calendar changes.
- Never alone: money movement, deletions, anything public-facing.
Then connect the fewest apps that do the job. 4,000 integrations is a catalog, not a plan. Every connection is a credential that a background process holds while nobody watches.
Key takeaways
- OpenAI Dots are always-on agents on GPT-6 Astra, each with its own cloud computer and access to 4,000+ apps
- Pro and Business Premium include one dot; Enterprise gets a beta via admin opt-in; extra dots have no published price yet
- Background research is read-only; task execution follows custom rules that either act alone or require approval
- For your business: write the approval rules before you connect apps, and keep money, deletions, and customer-facing sends behind a human
An agent is only as safe as its permission map. We scope agent access, write approval rules, and build the audit trail so you can see what ran at 3 AM. See how we build agent systems or have us map your permissions.
Sources: 9to5Google, Associated Press via KSAT, OpenAI.
- #openai
- #dots
- #ai-agents
- #approvals
- #chatgpt
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Trintech's finance agents execute inside your controls
Trintech launched three AI agents for financial close that do the work instead of recommending it — inside existing approvals and audit trails. Copy the pattern.
Read itSpaceXAI Team Bots: one shared agent holds the credentials
SpaceXAI opened Team Bots in public beta — shared AI agents with team memory, plugins, third-party credentials, and their own Slack handle. Scope them now.
Read it