# A deep dive into OpenAI dots

> OpenAI dots are always-on ChatGPT agents with their own cloud computer. How to set one up, give it work, connect apps and Codex, and control what it does.

Author: [Flavio Copes](https://flaviocopes.com/about/) | Published: 2026-09-30 | Topics: [AI](https://flaviocopes.com/tags/ai/) | Canonical: https://flaviocopes.com/openai-dots/

OpenAI dots are always-on agents that live in ChatGPT. You give your dot a responsibility, like keeping a launch on track or following up on bug reports, and it keeps working on it between conversations. It has its own computer and browser in the cloud, it uses the apps you connect, and it messages you when it needs a decision.

OpenAI announced dots at DevDay on September 29, 2026. They run on GPT-6 Astra, OpenAI's flagship model, and they're rolling out to ChatGPT Pro and Business Premium users, with a beta for Enterprise workspaces.

I haven't had access to a dot yet. This guide is built from what OpenAI had published by September 30, 2026: the launch post, the dots documentation, the Help Center FAQ and the GPT-6 Astra system card. When I get to try one, I'll add what I find.

OpenAI hasn't announced an API for dots. You talk to yours in ChatGPT, in Slack, in Microsoft Teams or on a voice call, so the examples in this guide are instructions you paste into a conversation, not code.

## What a dot is

A normal ChatGPT conversation waits for your message, answers it, and stops. A dot takes on work that continues. Once you hand it something, it tracks progress, works out what needs to happen next, and follows through as things change. You can come back days later with new information and it picks up from there.

Every dot has:

- its own cloud computer and browser, which keep working when your laptop is off
- access to the plugins you connect (OpenAI says more than 4,000 apps)
- its own notes about your preferences, decisions and ongoing work, on top of ChatGPT memory
- background agents it can split a job across
- a name, a handle and a look you choose

A dot is more of a coordinator than a worker. The [documentation](https://learn.chatgpt.com/docs/dots) says it can "use background agents, start new cloud threads, and create Work or Codex tasks on a connected computer". For heavy jobs it hands the work to ChatGPT Work or Codex, checks what comes back, and reports to you.

```mermaid
flowchart TB
  you[You] --> channels[ChatGPT, voice, Slack, Teams]
  channels --> dot((Your dot))
  dot --> agents[Background agents]
  dot --> cloud[Cloud computer and browser]
  dot --> plugins[Plugins: Gmail, Drive, GitHub]
  dot --> tasks[Work and Codex tasks]
  dot -.-> mac[Your computer, if connected]
```

The example OpenAI picked from its early testers is a small one. A tester's dot noticed he had forgotten to invoice a publication, prepared the invoice, and sent it after he approved it. He didn't ask for that. The dot spotted it while looking through his connected apps for ways to help, and it still waited for his OK before sending anything.

## How dots differ from ChatGPT Work and Codex

The ChatGPT app now has several agents in it, and they overlap. This is how they relate:

| Product | What it does | How long it lasts |
| --- | --- | --- |
| ChatGPT chat | Answers your message | One conversation |
| ChatGPT Work | Does a task on your computer or in a cloud container | One task |
| Codex | Writes and runs code in a repository, locally or in a Codex cloud environment | One task, or a scheduled one |
| Your dot | Holds ongoing responsibilities and delegates to Work and Codex | As long as you keep it |

A dot doesn't replace Codex. When your dot needs code written, it creates a Codex task, the same kind you'd start yourself. If you haven't used Codex yet, my [complete guide to Codex](https://flaviocopes.com/codex/) covers the app, cloud environments and permissions.

The difference shows up in billing too. Talking to your dot doesn't count toward your ChatGPT usage limits. Tasks it starts in Work or Codex count toward those products' limits, as if you had started them.

## Who can use dots and what they cost

Dots are rolling out gradually, so an eligible account may not see them right away. As of September 30, 2026, these plans include them:

- **ChatGPT Pro** ($100, $200 or $500 a month), for users over 18 outside the European Economic Area, the United Kingdom and Switzerland
- **Business Premium**, a Premium seat on ChatGPT Business ($100 per user per month billed annually, $125 billed monthly), rolling out worldwide
- **Enterprise**, including Edu and Healthcare, as a beta that's off by default until a workspace admin turns it on

Free, Go and Plus don't have dots at launch. OpenAI says it plans to bring them to more users, without a date. Dots aren't available to anyone under 18.

Your first dot is included in the plan at no extra cost. The [launch post](https://openai.com/index/introducing-dots/) says the plan also has "an allowance for deeper work, with extended limits for the first month after launch". OpenAI hasn't published what that allowance looks like after the first month, so don't build a workflow that depends on today's limits.

Later, OpenAI says you'll be able to add more dots and pay to scale each one, either by making it faster or by raising how much work it can take on per month.

## Create your dot

You create a dot on a computer, in the ChatGPT desktop app or in ChatGPT in a desktop browser. Mobile web isn't supported. After setup you can use the same dot in the ChatGPT mobile app, once your app has the update that supports it.

1. Open dots in ChatGPT and follow the introduction.
2. Connect apps like email, calendar and files, or skip this and add them later.
3. In the desktop app, choose whether to connect your computer.

My advice for step 2 is to connect fewer apps than you're tempted to. Your dot reads the apps you connect even when you haven't asked it anything (more on this in the proactive research section), and you can't delete individual things it learned. The only full reset is deleting the dot. Start with the two or three apps your first job needs.

Step 3 can wait too. Connect your computer when a task needs local files or tools, which you can do later from the dot's profile.

When setup is done, your dot introduces itself. It looks at the context it has, like your ChatGPT memory and the apps you connected, and suggests where it could help. You can start talking to it right away while it gathers that context.

Then make it yours. You can give it a name and pick its shape, color, eyes, glasses and accessories, and change them whenever you want. Your dot starts with a handle like `@yourname-dot`, and naming it updates the handle. OpenAI's example is `@tibo-alfred` for a dot named Alfred.

## Give it a responsibility, not a request

This is the mindset change. With a chat, you ask a question and get an answer. With a dot, you describe something you want kept true over time, point it at the sources, and tell it when to bother you.

A good brief answers four questions:

- What should stay true or get done?
- Which sources should it read?
- What deserves your attention?
- What must it not do yet?

For the rest of this guide, picture a small web app you run on the side. Users report problems in a `#feedback` channel in Slack, the code is on GitHub, and support email lands in Gmail. You've added your dot to `#feedback` and connected Gmail.

Here's a first responsibility:

```text
Help me stay on top of user feedback for our app. Read the #feedback
channel in Slack and the support emails in Gmail from the last two
weeks. Group the reports by problem, count how many people hit each
one, and link the original messages. Tell me which ones look like bugs
and which are feature requests. Don't reply to anyone.
```

The last line matters. Asking your dot to read and summarize doesn't give it permission to answer users, and saying so out loud removes any doubt.

Read the first result carefully and correct what's missing before you widen the job:

```text
The "can't log in" reports are two different problems: the password
reset email never arrives, and the Google login redirects to a blank
page. Split them. From now on, keep this summary current as new
reports come in.
```

Now the dot owns the summary. You don't need to open a new conversation for every update, because the next message builds on everything so far.

## Keep the work going: follow-ups, schedules and events

A dot comes back to work in three ways.

The default is that it decides by itself. The docs say it can "decide when to pause and wake up to continue work", so you don't need a schedule for every follow-up. If it's waiting for someone to reply to an email, it checks back later on its own.

When timing matters, ask for a fixed schedule. Include the time zone, how long the schedule lasts, what deserves a notification and where to deliver it. Then ask it to confirm what it saved:

```text
Every weekday at 9:00 Rome time for the next four weeks, check
#feedback and the support inbox for new reports and update the
feedback summary. Message me in ChatGPT only if a new bug affects
more than three people or blocks sign-ups. Confirm the schedule.
```

You'll find saved schedules under **Scheduled** in your dot's profile. You can also ask the dot to list, change or cancel its scheduled tasks.

The third way is an event. When a connected service supports it, your dot can react to something happening instead of checking on a timer:

```text
When someone posts a new bug report in #feedback, investigate it,
check whether it matches a problem already in the summary, and tell
me what you found. Confirm which events you can follow.
```

Two details trip people up here. Adding your dot to a Slack channel doesn't make it watch that channel: it only starts when you tell it what to watch for. And connecting Slack or any other app doesn't create a monitoring task by itself. Ask the dot to confirm, because not every service supports events.

While all this runs, your dot can split work across background agents that report back to it, and you can keep talking to it the whole time.

## Talk to your dot

You reach the same dot everywhere. Switching from ChatGPT to Slack doesn't create a second dot or reset what it knows.

### ChatGPT and voice

Message your dot in the ChatGPT desktop app, in ChatGPT in a desktop browser, or in the mobile app. To call it, open its conversation and press the phone button, or select **Call** in its profile in the desktop app.

A call is good for talking through a decision, changing priorities or asking for a progress update. You can type messages during the call too. Ending the call ends the voice conversation, and the work you assigned can continue.

Your dot can message you with progress or questions, but it can't call you yet. OpenAI says calls started by the dot are planned for after launch.

### Slack and Microsoft Teams

Open your dot's profile and select **Add** to connect a contact method. In Slack you can send it a direct message, or add it to a channel and mention it in a thread. Teams works for messaging too. Texting is coming soon.

By default your dot answers only you in Slack. You can tell it to engage with other people, and it still checks with you privately before sharing something you told it in private.

Tell it where different updates should go:

```text
Keep routine progress in ChatGPT. Bring decisions to me in Slack,
and message me there right away if a deadline is at risk.
```

Each channel keeps its own messages. A message you sent in ChatGPT doesn't appear in your Slack DM. The dot still uses what it learned in one place when it works in another.

### ChatGPT Space

If you use ChatGPT Space for shared pages, type `@` in a page and choose your dot, or write `@dot` followed by your request inline or in a comment. It can draft, research and revise the page. Review the changes before you continue, since collaborators on the same page may use different agents.

## Its computer and yours

### The cloud computer

Your dot's cloud computer is where it browses, runs software and keeps files. Open your dot's profile and look under **Computers** to see it.

Opening the computer lets you watch. To use it yourself, select **Take over**, and **Return control** when your dot can continue. That's useful when you want to check what the browser is showing or do one step by hand.

The computer keeps its state between uses, with its own files, software and browser sessions. Being logged in to a website on your laptop doesn't log your dot in.

### Signing in to websites

When a website needs a login, your dot sends you a sign-in request with a private form. You type your credentials and any verification code there, and the form sends them to the remote browser outside the conversation, so the model never sees them.

You can also choose to sign in yourself in takeover mode and select **Done** when you finish.

When it's offered, **Save to Passwords** saves the login for later. That's optional. If your dot wants to use a saved login for a new sign-in, it asks you to confirm first. An active session is different: your dot keeps using it until you sign out or the website expires it.

These protections only cover the sign-in flow. A password you paste into a chat message or a document isn't protected the same way, so don't do that.

Some websites block cloud browsers. In that case you can ask your dot to try your connected computer. That creates a separate task on your computer, and the cloud browser's session doesn't move over.

### Connecting your computer

Connecting your computer gives your dot access to local files, code and apps. You do it once:

1. Open your dot's profile in the ChatGPT app on that computer.
2. Under **Computers**, find **Your computer** and select **Allow access**.
3. Review the confirmation and select **Allow access** again.

A few rules apply. You can connect only one personal computer at a time. The computer has to be online with the ChatGPT app open while your dot uses it. **Offline** only means it's unavailable, and the permission stays in place until you select **Revoke access**.

This permission is separate from connecting your computer to Codex or turning on Work Sync. Neither of those gives your dot access. If you want your dot to use your camera, microphone or screen, you also need to give the ChatGPT app that permission in your operating system settings.

The access follows your dot everywhere. If you message it from your phone, it can still work with files on your connected Mac.

### Plugins

Your dot uses the same plugins as ChatGPT, ChatGPT Work and Codex, with the same permissions. You manage them in the **Plugins** tab in ChatGPT. Connect Gmail and your dot can find email, connect Google Drive and it can work with documents, connect GitHub and it can investigate issues and prepare pull requests.

Permissions go down to the action. You can let your dot read email without letting it send email, which is how I'd start. If a connection expires, your dot asks you to reconnect before it continues.

Skills that live on your computer need a connected computer.

The three kinds of connection are separate, and that's easy to forget:

| Connection | What it enables |
| --- | --- |
| Messaging channel | Talk to your dot and receive updates there |
| Plugin | Use that service's information and tools, within its permissions |
| Your computer | Work with that computer's files, apps and tasks while it's online |

Messaging your dot in Slack doesn't give it your inbox. Connecting Gmail doesn't give it your laptop.

## Use your dot for coding work

Here's where dots meet the tools developers already use. When code needs writing, your dot creates a task for it, and there are three kinds:

| Task | Where it runs | What it needs |
| --- | --- | --- |
| New cloud coding task | A Codex cloud environment | An environment you already created. Your computer can be off. |
| New local Work or Codex task | Your connected computer | The computer online with the ChatGPT app open |
| Existing local Codex task | Your connected computer | You tell the dot which task and what to change |

For cloud coding, create the environment in Codex first. On the web or in the desktop app, start a new task, choose **Work in** > **Cloud**, open **Select environment** and select **Create environment**. Pick the GitHub repositories, and Codex inspects them, installs dependencies and tests the setup with you. When it works, select **Publish**. The [cloud environments docs](https://learn.chatgpt.com/docs/environments/cloud-environments) cover secrets, network access and private networks.

With the environment published, back to our feedback example. The dot confirmed that the Google login redirects to a blank page, and several users reported it:

```text
The blank page after Google login is confirmed. Use the Codex cloud
environment for our app's repository to find the cause and fix it.
Add a test that fails without the fix. Open a draft pull request and
send me the link. Don't merge anything.
```

The dot creates the Codex task and gives it the instructions and context it needs. The task doesn't receive every conversation you've had with your dot, only what the dot passes along. It shows up as its own thread in the desktop, web and mobile apps, so you can open it and steer it directly.

When the task finishes, the dot checks the result and can send follow-up instructions. OpenAI's launch example goes one step further: a dot that watches customer feedback, builds and tests small fixes, and brings you complete pull requests with a video showing the change.

For local work, point it at a task on your connected computer:

```text
Continue the Codex task on my Mac where we moved the settings page
to the new layout. Run the tests again and tell me what still fails.
```

Two warnings. A finished run doesn't prove the result is right, so read the diff and the test output like you would for any agent. And Codex tasks started by your dot count toward your Codex usage limits.

I'd let a dot open draft pull requests, but I'd keep merges to main for myself.

## Memory: what your dot knows

Your dot works from three kinds of information:

- the conversation it's working in, plus source material and tool results
- relevant ChatGPT memory
- its own saved notes about your preferences, decisions and ongoing work

The notes are the new part. They're separate from ChatGPT's saved memory and they're not a transcript. Your dot updates them as decisions change, and they carry across ChatGPT, Slack, Teams and calls.

Memory flows both ways with ChatGPT. Your dot receives your memories and recent conversation context, and your conversations with it can add memories to ChatGPT. Turning off Memory in ChatGPT stops that sharing, but it doesn't delete what your dot already received. Changing a ChatGPT memory setting doesn't necessarily change the notes your dot already made either.

Here's what you should know before you connect a lot of apps:

- You can't view, correct or delete individual dot memories. Deleting the dot is the only way to clear them.
- Disconnecting a plugin stops new access but doesn't delete what your dot already learned from it.
- Your dot's context doesn't keep credentials, images or screenshots.
- On a call, your dot uses a selection of the conversation context, which can differ from what a background task sees.

## Proactive research

When you aren't working with it, your dot looks for ways to help. OpenAI calls this **proactive research**. It reads information from the apps it has permission to read, keeps private notes about what it finds, and brings you a suggestion or a question.

The docs give an example: your dot might notice that a release decision conflicts with a draft you shared last week.

The tools used for this research are restricted. They can't send messages to people, change content in your apps, or control a browser or computer. If your dot wants to act on a finding, that follow-up goes through the same permissions and approvals as any other action.

This is where the invoice example came from, and on paper it's the part of dots that sets them apart from other agents. It's also why I'd keep the list of connected apps short. Everything you connect becomes material for this background reading.

## Permissions, approvals and Custom Rules

Your dot has several layers of protection, from the model up:

- GPT-6 Astra is trained to refuse harmful requests
- plugin permissions limit what it can reach
- Custom Rules set your own boundaries
- Auto-review checks certain actions before they run
- safety monitoring watches for harmful behavior while it works

### What always needs you

Some actions have fixed rules you can't change. Changing a password or transferring money means your dot hands the step over to you. Actions like permanently deleting data or installing software may need your approval each time. For some actions, like sending recurring messages, you can approve in advance.

Your dot can also buy things with a card you saved on a merchant's website. Purchases need your approval, which you can give in advance only if it specifically covers that purchase.

### Auto-review

Before your dot takes an action that could affect your accounts or share information, a separate review checks it against your instructions, your permissions, your Custom Rules and OpenAI's safety requirements. The review decides whether the action runs, needs your approval, or is a step you have to do yourself.

The Help Center gives a concrete case: before your dot sends an email, Auto-review checks the recipient and the message to catch a wrong address or something you didn't mean to share.

```mermaid
flowchart TB
  action[Your dot wants to act] --> review{Auto-review}
  review -->|within your instructions| run[The action runs]
  review -->|needs a decision| ask[It asks you to approve]
  review -->|sensitive step| you[You do it yourself]
  review -->|blocked| alt[Safer path, or it stops]
```

If an action is blocked, your dot may ask you to clarify, try a permitted alternative, or stop. Your approval can't override the core safety requirements, and your dot can't switch Auto-review off.

If you know Codex, this is the same idea as Codex's [Auto-review](https://learn.chatgpt.com/docs/sandboxing/auto-review), where a separate reviewer agent decides on actions that cross the sandbox boundary. OpenAI added instructions specific to dots to the reviewer's policy.

### Scope your instructions

Most of the time you don't need a rule. A clear instruction does the job, as long as it says who, what and when.

Approving one message doesn't give your dot ongoing permission to contact people. If you want a recurring action, describe exactly what's covered:

```text
Every Friday at 17:00 Rome time, post the feedback summary in the
#team channel in Slack. Only include what's already in the summary.
Ask me first if you want to add anything else or post anywhere else.
```

That approval covers one channel, one kind of message and one time. Anything outside it needs another decision from you.

### Custom Rules

Custom Rules are for boundaries you want to hold across everything your dot does. After setup, open **Settings** > **Personalization** and select **Custom rules** under **Permissions**. Select **Add**, describe the action, choose how your dot should handle it, and select **Add rule**.

There are four choices:

| Rule | What your dot does |
| --- | --- |
| Take action without asking | Does it without asking |
| Take action when you say so | Does it when you explicitly ask, otherwise asks first |
| Ask before taking action | Asks for approval every time |
| Hand off to you | Asks you to do it yourself |

For the app in our example, I'd start with something like this:

| Action | Rule |
| --- | --- |
| Replying to a user or customer | Ask before taking action |
| Posting in a shared Slack channel | Ask before taking action |
| Opening a draft pull request | Take action when you say so |
| Merging a pull request | Hand off to you |
| Deleting shared files in Google Drive | Hand off to you |

Rules are instructions your dot tries to follow, and it can make mistakes. They also have limits. A rule can't give your dot access to an app or your computer, can't override the built-in safety requirements, and can't remove required confirmations like the one for using a saved login. It can't change Auto-review or the restrictions on proactive research either.

Plugin permissions are a separate control. Select **Open Plugins** from the rules screen to see them. Use your conversation for preferences like writing style, and rules for when your dot can act. If your company disables Custom Rules for the workspace, your saved rules stop applying.

## Review, pause and stop

In the desktop app, open your dot's profile and select **Activity**. Each task shows its progress, files and results, including background work. If a task is waiting for a decision, a sign-in, an app connection or an approval, open the request and answer it so the work continues.

The quickest check is to ask:

```text
What are you working on right now, and what needs my input?
```

Stopping has three separate controls, and they do different things:

- **Pause** stops your dot's current main task. It doesn't necessarily stop delegated tasks, and it doesn't cancel future scheduled runs. **Resume** continues it.
- To stop a delegated task, open it in **Activity** and stop it there.
- To end a recurring task, disable or delete it in **Scheduled**.

Stopping doesn't undo actions already completed. If your dot made a mistake, ask it to fix it. It may be able to revert edits to a document or recall an email, but some actions can't be undone.

### Delete your dot

**Delete** removes your dot and its own context, and it can't be undone. Read the confirmation before you accept, and save any results you want to keep.

Some things survive. Files, Codex threads and ChatGPT conversations your dot created are stored separately and stay where they are. Anything your dot added to ChatGPT memory stays there too, and you manage it in ChatGPT's Memory settings. Deleting the dot doesn't undo changes it made in your apps or recall messages it already sent.

## Privacy and your data

For ChatGPT Business, Enterprise and Edu workspaces, OpenAI doesn't use your data to train its models by default.

On personal plans like Pro, the **Improve the model for everyone** setting controls whether your dot's conversations and work can be used for training. According to the [dots privacy FAQ](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs), that includes actions your dot takes, work it delegates to other agents, automations you set up, and data from connected apps used in your conversations. OpenAI says it removes personal identifiers where possible.

OpenAI doesn't train directly on proactive research or your dot's private notes. If something from that research ends up in a conversation or a task, your training setting applies to it.

Two more things from the FAQ. People at OpenAI may review your dot's activity in limited cases, including safety cases, even with training turned off. And your content is encrypted when stored and while it moves between you, OpenAI and its service providers.

## How safe is it?

OpenAI published a dots appendix in the [GPT-6 Astra system card](https://deploymentsafety.openai.com/gpt-6-astra/sec%3Aappendix-dots). It's OpenAI testing its own product, so read it that way, but the numbers say where the risks are.

The big worry with an agent that reads your email all day is **prompt injection**: an email written to trick the agent into leaking data or paying someone. OpenAI fed dots 100 runs of 500 simulated emails each, 16,600 of them attacks written by an internal red-teaming model. No attack succeeded. In a second test, where the attacker refined its email after each failure, 2,638 attempts produced no success either.

Human red-teamers also attacked dots, often posing as coworkers, websites or other agents. OpenAI updated its confirmation policies based on what they found and retested those scenarios. Their attempts to pull out sensitive data, including sending data from an `openai.com` address to a `gmail.com` address, all failed.

The weaker area is the one that makes dots useful: working for a long time on many things. In a test where a dot handled a chain of related tasks and the permitted scope changed between tasks without anyone saying so, the rate of moderate scope violations went from 8.6% with five tasks in between to 19.7% with ten. A moderate violation is something like carrying information from one task into an unrelated one, or editing a shared document it shouldn't have touched. There were no severe breaches.

In another test, a permission was revoked or the scope changed while a task was running. The dot adapted in all 17 cases where the change was explicit, and passed 45 of the 49 episodes overall. The four it missed had some ambiguity about where the boundary was.

What I take from this: keep each responsibility clearly scoped, and don't pile loosely related jobs onto the same thread of work. The more the dot juggles, the more likely something from one job leaks into another. OpenAI's own FAQ doesn't claim prompt injection is solved either, only that these protections lower the risk.

## Specialist dots and what comes next

Your dot works for you. **Specialist dots** are a different thing, meant to take on a role inside a company. Each gets its own identity, credentials and access to the systems it needs, and OpenAI is previewing IT-provisioned hardware and deep integrations with a company's systems of record.

OpenAI says it tested this internally in procurement, invoice processing, email marketing, customer support and commercial contracting. It's starting with focused enterprise pilots where OpenAI engineers work with each company to define the dot's responsibilities, its tools and how people approve its work. OpenAI is also working with Microsoft to manage specialist dots through Microsoft Agent 365, next to the security and governance tools companies already use.

Longer term, OpenAI talks about teams of dots working together on your behalf.

## For workspace admins

If you run a ChatGPT Enterprise workspace, dots are off until you enable them. The [admin guide](https://learn.chatgpt.com/docs/enterprise/o-admin-guide) and the [local access guide](https://learn.chatgpt.com/docs/enterprise/cloud-local-access) have the details. These are the points that matter most:

- Open **Workspace settings** > **Permissions & roles** and enable **Use dots** in the workspace default, or grant it through a custom role for specific groups.
- Slack participation, custom rules and local computer access are separate permissions. Local access is its own switch, **Allow local computer access** under **Use Dots**, and users need the ChatGPT desktop app version 26.929 or later for it to work.
- Under **Cloud computer capabilities**, decide on cloud browser use, cloud network access and cloud computer use. These settings are shared with Work Cloud, and each one is configured on its own.
- Dots aren't available for FedRAMP workspaces, workspaces with EKM, or workspaces with inference residency set to the UAE. During the beta they don't support data residency, and they don't offer zero data retention.
- Use the Analytics API for usage and the Compliance API for audit records. Cloud orchestration events don't reach your OpenTelemetry collector.
- Hooks you rely on in local Codex workflows may not run. Dots use admin-managed remote MCP hooks, and command, prompt and agent hooks aren't supported with cloud orchestration.

After you grant the permissions, each member still has to connect Slack or their own computer.

## dots compared with Grok Bot, Cursor Projects and Muse

Dots arrive after several similar launches. This is how they line up:

| Product | Where you talk to it | Where the work happens | Built for |
| --- | --- | --- | --- |
| OpenAI dots | ChatGPT, voice, Slack, Teams | The dot's cloud computer, your connected computer, Codex | Ongoing responsibilities across your apps |
| [Grok Bot](https://flaviocopes.com/grok-bot/) | The Grok Bot desktop and mobile apps | One cloud computer per user, shared by all your Bots | Named Bots running skills on routines |
| [Cursor Projects](https://flaviocopes.com/cursor-projects/) | Cursor's Agents view | Coding agents the coordinator starts | Long-running coding work |
| [Meta Muse](https://flaviocopes.com/ai-news/#meta-muse) | The Muse app and WhatsApp | Meta's cloud | Personal errands like email, travel and forms |

Grok Bot is the closest match. Both give an agent a persistent cloud computer that works on a schedule and asks before sensitive actions. Grok Bot has you create several named Bots, each with its own role, and teach them reusable skills. A dot is one agent that collects responsibilities, splits them across background agents, and is built into ChatGPT, Slack and Teams, where you already talk to people.

Cursor Projects shares the coordinator idea: one long-lived agent that plans and delegates instead of writing code itself. It's focused on code, and the work comes back as pull requests. I compared the two xAI and Cursor products in [Grok Bot vs Cursor Projects](https://flaviocopes.com/grok-bot-vs-cursor-projects/).

Muse is Meta's consumer agent, closer to a personal assistant for errands than to a work tool.

If you want to understand what's going on underneath all of these, the free [AI Fundamentals course](https://flaviocopes.com/courses/ai-fundamentals/) covers how agents use tools, and the [MCP course](https://flaviocopes.com/courses/mcp/) covers how they connect to other services.

## How I would use a dot

I don't have a dot yet, so this section is about how I would use one once I do.

What would decide it for me is the Codex connection. Codex is where my terminal and server work already happens, and a dot that can start Codex tasks sits right on top of that.

The first job I'd give it is watching this site after posts go live. My posts are scheduled and appear when the site rebuilds. A dot could check each new post after its rebuild: that it's live, that it's in the blog list and the RSS feed, and that its links resolve. It would only message me when something fails, with the failed check and the URL. That's read-only work, so the dot never needs permission to change anything.

The second is keeping my living tool guides current. The [Codex guide](https://flaviocopes.com/codex/), the [Grok Bot deep dive](https://flaviocopes.com/grok-bot/) and the [Cursor Projects guide](https://flaviocopes.com/cursor-projects/) go stale every time those products ship a change. Proactive research fits this well. The dot would read the official docs and changelogs, and when something changes it would tell me which sentence in which post is now wrong, with a link to the source. After I say yes, a Codex cloud task in this site's repository would prepare the edit as a draft pull request.

The third is preparing my newsletter. On my connected Mac, a Codex task could collect everything I published since the last issue and create a draft campaign in Sendy. The send button would stay mine, as a **Hand off to you** rule.

Some things I wouldn't give it. Anything involving money, like refunds, and anything involving student data or course access stays with me. And I wouldn't duplicate jobs that already run elsewhere: the pricing checks for [HostingPicker](https://hostingpicker.dev) and [Payment Processor](https://paymentprocessor.dev) already run as a Grok Bot routine, and I'd rather have one agent own each job.

## What I don't like

These come from reading the docs, not from using a dot.

You can't see what your dot has noted about you, and you can't delete one wrong note. The only reset is deleting the whole dot. For an agent that reads your email in the background, I'd want a way to see and edit its notes.

The pricing after the first month is unknown. "An allowance for deeper work" is not a number, and until OpenAI publishes the terms it's hard to plan real work around a dot.

Pro users in the EEA, the UK and Switzerland don't get dots at launch, and OpenAI hasn't said when they will.

And you can connect only one personal computer at a time, which matters if your work is split between a laptop and a desktop.

## Where to start

Pick one thing you check by hand every week, like support email, a feedback channel or a project deadline. Give your dot that single responsibility, connect only the apps it needs, and tell it to draft instead of act.

Read what it brings back for a few days. When the drafts are right, add a schedule, and only then a Custom Rule that lets it act without asking.

The official [dots documentation](https://learn.chatgpt.com/docs/dots) has the current details, and the [privacy, security and safety FAQ](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs) is worth reading before you connect your email.
