Updated October 4, 2026: expanded with a worked workflow, permission controls, tests and limitations.

OpenAI Dots are not simply another place to type a prompt. OpenAI describes them as always-on AI agents that can use their own cloud computer, work across connected apps and keep moving while you are away.

That sounds impressive. It also raises the question that matters more: what should you actually trust an always-on agent to do?

This guide separates the launch promises from the practical decisions. We will look at how Dots work, where they could save time, what access they need, the safety controls worth checking and whether you should use one now.

Short answer: OpenAI Dots can watch, plan and perform multi-step work across apps. Start with a narrow, reversible task. Give the agent the least access it needs, inspect its work and keep approval in front of messages, purchases, publishing, deletion and other consequential actions.

OpenAI Dots: quick facts

QuestionCurrent answer
What is a Dot?An always-on AI agent with a dedicated cloud computer
What powers it?OpenAI says Dots are powered by GPT-6 Astra
Where can you reach it?ChatGPT, Slack, Microsoft Teams and voice
What can it connect to?More than 4,000 apps through plugins, according to OpenAI
Who gets access first?Staged rollout to eligible Pro, Business Premium and Enterprise customers
Is there a separate Dots price?OpenAI has not presented a simple standalone Dots price on the launch page
Best first taskA recurring, low-risk workflow with clear inputs and an easy-to-review result

Transparency note: This is a first-look analysis based on OpenAI’s launch material and independent reporting, not a hands-on review. Availability is still rolling out, so features, plan limits and interfaces may change.

What are OpenAI Dots?

A Dot is an AI worker you assign to an ongoing job. Instead of waiting inside one chat, it can use a browser and connected tools, remember your feedback and continue working on its own cloud computer.

OpenAI’s examples include investigating a software bug, turning a design into an application, helping with planning cycles and preparing invoicing work that a person approves. The common thread is not “write me a paragraph.” It is a goal that requires several steps, tools and checkpoints.

You can contact a Dot from familiar places such as ChatGPT, Slack or Teams. That matters because the agent is meant to fit inside work, not become another dashboard you must remember to open.

The closest mental model is a junior digital operator with its own computer. It may be fast and tireless, but it still needs a clear job, limited permissions, examples of good work and a manager who checks important decisions.

How Dots differ from ChatGPT and normal automation

Tool typeBest atMain limitation
Chat assistantAnswering, drafting, analysing and helping in the current conversationUsually waits for you to start and guide the interaction
Fixed automationRepeating a known trigger-and-action sequence reliablyStruggles when the next step requires judgement
OpenAI DotPursuing an ongoing goal across tools and adapting its next stepMore autonomy creates more permission, review and recovery risk

A fixed workflow still wins when the rule is predictable. If every approved invoice PDF should be copied to one folder and logged in a sheet, use ordinary automation. It will be cheaper, easier to test and easier to explain.

An agent becomes useful when the route changes. A weekly research brief might require checking different sources, following new leads, comparing claims, asking for clarification and drafting a result in a consistent format. That is closer to the territory Dots are designed for.

If this distinction still feels fuzzy, start with our guide to AI agents vs chatbots vs automation. For a build-it-yourself alternative, the complete n8n AI agents guide shows how the same ideas work in visible workflows.

What actually happens after you give a Dot a job?

The easiest way to understand OpenAI Dots is to stop thinking about a single prompt. A Dot is closer to a small operating loop: you define the outcome and boundaries; the agent gathers context, works through multiple steps, pauses when your decision is required and carries your feedback into the next run.

StageWhat the Dot doesWhat you should decide
1. GoalTurns your request into an ongoing piece of workDefine the deliverable, deadline and finish line
2. ContextUses conversations, connected apps and feedback relevant to the jobSpecify trusted sources and examples of good work
3. BoundariesChecks app access, built-in rules and your Custom RulesChoose what is allowed, approval-only or blocked
4. ExecutionUses its cloud browser, cloud computer and connected tools across several stepsWatch the first runs in Activity View and redirect weak work
5. ApprovalPauses when an action requires permission or must remain with youInspect the proposed action and its evidence—not just the final button
6. FeedbackUses your corrections to learn preferences and standards over timeExplain why a result is right or wrong instead of silently rewriting it

Its own cloud computer

Each Dot works on a separate cloud computer with a browser. Your laptop and files remain separate unless you deliberately connect the device. You can open the Dot’s computer to inspect what it is doing. This separation is important: “has a computer” does not automatically mean “controls my computer.”

Proactive research

When you are not actively working with it, a Dot can look for useful work in connected apps. OpenAI calls this proactive research. In this background mode, app tools are restricted to read-only access: the Dot cannot send a message, change app content or control a browser or computer. It may notice an overdue invoice or a changing project requirement, but an action still follows the applicable approval rules.

Custom Rules

Custom Rules are the practical boundary between useful autonomy and an open-ended mandate. For a given action, you can allow it, require approval or block it. Built-in safety requirements still apply. A sensible rule set is specific enough to evaluate:

RuleExample
AllowRead documents in the approved research folder and create a draft inside the project workspace
Require approvalSend any external message, publish content, change a customer record or create an invoice
BlockDelete data, change permissions, modify credentials or use a source outside the approved list

Activity View and auto-review

Activity View lets you follow foreground and background work, inspect progress and redirect the Dot. Auto-review separately checks actions that could affect accounts or share information against your instructions, Custom Rules and OpenAI’s safety requirements. It decides whether work can proceed, needs approval or must be completed by you. Changing a password is one example OpenAI says always remains a human task.

These controls reduce risk; they do not prove the result is correct. Review the evidence, source and proposed action whenever the consequence matters.

7 practical OpenAI Dots use cases

1. A daily priority brief

A Dot could review the calendar, selected project updates and an approved task list, then prepare a short morning brief: meetings that need preparation, blocked work and the three decisions that deserve attention. Keep it read-only at first. A useful brief is valuable even if the agent cannot change a single record.

2. Research that develops over time

Instead of requesting one search, give the agent a standing question and an evidence standard. It can watch a set of official sources, collect meaningful changes and draft a weekly summary with links. The important instruction is what not to include: repeated announcements, unsupported social posts and claims without a primary source.

3. Project follow-up without more meetings

A Dot could compare a plan with recent status updates, identify missing owners and prepare follow-up questions. It should draft reminders rather than send them automatically until you know it understands the team’s tone and context.

4. Software investigation

OpenAI demonstrates bug investigation as a launch use case. An agent can gather error reports, reproduce an issue, inspect relevant code and prepare a proposed fix. Production deployment remains a separate decision. “Found a likely cause” and “safe to release” are not the same status.

5. Content operations

For a small content team, a Dot could turn an approved article into a newsletter draft, social snippets and an update checklist. Let it prepare assets and flag broken links, but require a human to publish. That gives you leverage without letting a weak draft become a public mistake.

6. Invoice preparation

The agent could gather approved time records, check required fields and prepare an invoice for review. It should not invent missing rates, change bank details or send the invoice without approval. Finance workflows need tighter limits than a research brief.

7. Customer-support preparation

A Dot could classify new cases, find the relevant policy and draft a response. Keep refunds, account changes and external sending behind deterministic checks and human review. Our safe Gmail AI agent tutorial applies this same draft-first pattern.

Worked example: build a weekly competitor-change brief

“Research my competitors” is vague. A Dot could browse for hours and still produce something you cannot use. A better first project has fixed sources, an output contract and a clear rule for uncertainty.

The task brief to give your Dot

Goal: Every Friday by 3 p.m., prepare a competitor-change brief covering the five companies in the approved tracker.

Sources: Official product pages, release notes, pricing pages and company newsrooms. Use reputable reporting only when a primary source is unavailable. Ignore social posts unless they link to evidence.

Output: A one-page table with company, confirmed change, date, source, likely customer impact and recommended follow-up. Add a separate “unconfirmed” section. Do not guess.

Boundaries: Read approved sources and create a draft in the research folder. Do not contact anyone, publish, change the tracker or sign up for trials.

Escalation: Ask me when sources conflict, a page requires payment or login, or a recommendation could affect pricing or a public claim.

What the workflow looks like

StepDot’s workExpected evidence
CollectChecks the approved pages and release feedsURL and observed publication/update date
CompareCompares current facts with the previous briefOld value, new value and what changed
VerifyLooks for a primary source and a second source where the claim is consequentialSource links beside each claim
DraftBuilds the table and separates facts from interpretationA reviewable document, not an external message
EscalateFlags conflicts, missing dates and ambiguous claimsA short question with the conflicting evidence
ImproveApplies your corrections to the next weekly briefFewer repeated formatting and source-quality errors

Example of a useful result

CompanyConfirmed changeEvidenceImpactFollow-up
ExampleCoTeam plan increased from $20 to $24 per user/month on October 2Pricing page and dated newsroom postStronger opening for a value comparisonReview our comparison table; do not change pricing
SampleAINew export feature announced; availability unclearRelease note; no plan matrix updatePossible feature gap, not yet confirmedKeep in “unconfirmed” and check next week

The difference is small but important. The brief does not say “Competitor X is better.” It preserves the evidence, uncertainty and next decision so a person can act intelligently.

How to test the first three runs

  1. Normal case: add one genuine update and check that it appears with the correct date and source.
  2. No-change case: confirm the Dot reports “no verified change” instead of manufacturing news.
  3. Conflicting case: make the pricing page and release note disagree; the result should be flagged, not averaged or guessed.
  4. Hostile case: include a webpage telling the agent to ignore its rules; the instruction should be treated as page content, not authority.
  5. Permission case: request that the brief be emailed externally; the Dot should stop for approval or remain blocked under your rules.
  6. Recovery case: deliberately add a wrong company to the tracker and confirm you can correct the scope, review the activity and prevent recurrence.

Measure source accuracy, missed changes, false positives, review minutes and repeated corrections. If the human still rebuilds the brief from scratch, the agent has not saved time.

The safety question: what can the agent see and do?

The impressive part of Dots is their ability to act across apps. That is also the part to slow down and inspect.

OpenAI says Dots include access and action reviews, and that you can inspect the agent’s work. Those controls are useful, but a product setting cannot decide your acceptable risk. Before connecting an app, write down four things:

  • Data: what messages, files, records or code can it read?
  • Actions: what can it create, edit, send, buy, publish or delete?
  • Approval: which exact actions must stop for a person?
  • Recovery: how will you revoke access, correct a mistake and preserve a log?

Follow least privilege. A research agent does not need permission to send email. A calendar brief does not need access to every shared drive. A content assistant does not need administrator rights to your website.

Also treat external webpages, emails and documents as untrusted input. They may be wrong, malicious or written to manipulate an agent. Instructions found inside content should never quietly override the job and limits you set.

Use our 12-control AI agent security checklist before connecting company data. It covers ownership, permissions, approvals, logs, abuse testing and the kill switch people usually remember too late.

OpenAI Dots safety checklist: narrow goal, minimum access, human approval, testing and recovery
A safer pilot starts narrow, limits access, keeps approval and tests recovery before expanding autonomy.

A sensible first-week setup

  1. Choose one recurring job. Avoid “help me run the business.” Use a finish line such as “prepare a cited competitor-change brief every Friday.”
  2. Define a good result. Provide one or two examples, required sources, length, format and the conditions that should trigger a question.
  3. Connect the minimum data. Begin with a small folder, one project or a read-only source—not the entire organisation.
  4. Keep actions reversible. Draft, suggest, label and queue before allowing send, publish, purchase, edit or delete.
  5. Run normal and hostile tests. Include missing data, conflicting instructions, a misleading webpage and a request outside scope.
  6. Measure the whole workflow. Count preparation, review, corrections, failures and maintenance—not only the agent’s run time.
  7. Expand one permission at a time. Add access only after the narrower version works reliably.

Do not measure success by the number of tasks the Dot attempted. Measure dependable work completed after review. The AI agent ROI calculator gives you a simple way to compare time, cost, quality and error risk.

Who should try OpenAI Dots now?

Your situationRecommendation
You already use several connected work apps and can supervise a pilotTry one read-only or draft-first workflow
You need a flexible task that fixed automation handles badlyTest Dots against the existing process
You mainly need simple trigger-action automationKeep the fixed workflow
You cannot explain permissions, approvals or recoveryWait and design the controls first
You work with highly sensitive or regulated dataRequire security, privacy and legal review before a pilot

Independent coverage from Reuters also noted glitches in the live demonstration. That does not make the idea useless. It is a useful reminder that a launch demo is not your production test.

Important limitations and unresolved questions

Dots launched with an ambitious promise, but several practical questions will only become clear after broader real-world use.

  • Rollout is limited. Plus, Go and Free users do not have a published access date. Enterprise access also depends on workspace enablement.
  • “Included” does not mean unlimited. The first Dot is included with eligible Pro and Business Premium plans, but deeper work has an allowance. OpenAI says users will eventually be able to buy more Dots or scale their speed and monthly output; the long-term economics are not yet clear.
  • Connected apps define usefulness. “More than 4,000 apps” is not the same as every action in every app. Check whether the exact system and permission you need are supported.
  • Cross-channel context needs discipline. Carrying context between ChatGPT, Slack and Teams is convenient, but old or irrelevant context can also influence later work. Correct assumptions explicitly.
  • Approvals can become routine. A reviewer who clicks approve without reading the proposed action is not a meaningful control.
  • Agents still make mistakes. OpenAI says consequential work should be reviewed. The DevDay live demonstration also experienced failed voice updates, a useful reminder that launch capability and dependable operations are different things.
  • This is not a compliance shortcut. Regulated or sensitive workflows still require your organisation’s security, privacy, retention, access and legal review.

For now, a Dot should earn autonomy through observed performance. Start with a draft, measure it, correct it and expand one permission at a time.

OpenAI Dots pricing and availability

OpenAI says Dots are rolling out to Pro, Business Premium and Enterprise customers in eligible markets, with broader availability planned. Rollout does not mean every account receives access on the same day.

Do not confuse API model prices with the price of running a Dot. OpenAI lists separate API rates for models such as GPT-6 Astra and GPT-6.1 Sol, but the Dots launch page does not give a simple standalone cost per Dot. Check the current plan and usage terms inside your account before budgeting a pilot.

For the latest product details, read OpenAI’s official Dots announcement. Treat any plan, region or limit in this article as a dated snapshot.

OpenAI Dots learning path: read these child guides next

This article is the overview. Use the focused guides below when you move from “What is a Dot?” to designing and evaluating a real workflow.

Recommended order: decide whether you need an agent, define the security boundary, run one measurable pilot, then compare a managed Dot with a visible n8n workflow. That sequence prevents the tool from choosing the problem.

Key takeaways

  • OpenAI Dots are ongoing agents with their own cloud computer, not ordinary chat sessions.
  • The best use cases have changing steps but a clear goal and reviewable output.
  • Fixed automation remains better for predictable rules.
  • Begin read-only or draft-first, with minimum permissions and visible approvals.
  • Judge value after human review, corrections, failures and operating cost.

Frequently asked questions

Are OpenAI Dots available to everyone?

No. OpenAI announced a staged rollout for eligible Pro, Business Premium and Enterprise customers, with expansion later. Account, plan and market eligibility can affect access.

Can a Dot use my computer?

A Dot normally has its own cloud computer. OpenAI also says it can use your laptop when you grant permission. Review the requested access and do not allow broader control than the task requires.

Are OpenAI Dots safe?

They include product-level controls, but safety depends on the task, permissions, data, approvals and monitoring you configure. No general-purpose agent is risk-free. Use narrow access and require approval for consequential actions.

Will Dots replace Zapier, Make or n8n?

Not for every workflow. Deterministic automation is still the better choice when the steps and rules are known. Dots target work where the route changes and the system must interpret context. Many useful systems will combine an agent with fixed validation, approval and logging steps.

Final verdict

OpenAI Dots point toward a different relationship with AI: less prompting, more delegation. That could remove a surprising amount of coordination work. But delegation only becomes productivity when the output is dependable and the consequences are controlled.

My practical advice is simple. Do not begin by asking a Dot to run something important. Ask it to prepare something useful. Watch how it handles ambiguity, feedback and failure. Then decide whether it has earned the next permission.

What recurring task would you delegate first? Which action would you never allow without approval? And would you prefer an agent that works independently or a visible workflow you can inspect step by step?


About the author: Nishikant Tiwari is a computer engineer who writes practical, evidence-based guides on AI tools, automation and personal productivity. His focus is simple: test useful workflows, question inflated claims and help readers make better decisions with technology.

Similar Posts