News analysis · Published
OpenAI Dots: Give Always-On Agents an Authority and Recovery Test
By the ELYMENT AI editorial team · Free to read
OpenAI launched Dots on 29 September 2026 as always-on agents that can keep working across projects, cloud computers and connected apps. OpenAI also describes Custom Rules, activity monitoring, separate action review and mandatory human handoffs for some sensitive tasks. For business leaders, availability is not the same as production readiness. Give one bounded workflow a 30-day test that proves authority limits, approval behaviour, evidence quality, recovery and a clean shutdown path before expanding access.

What OpenAI launched with Dots
OpenAI says Dots are proactive assistants that can continue work between conversations, use their own cloud computer and browser, and operate through connected apps. They can be reached through ChatGPT, Slack and Teams, while specialist enterprise pilots are intended to use dedicated identities, credentials and systems access. The initial rollout covers eligible Pro, Business Premium and Enterprise users, with enterprise access controlled by workspace administrators.
The examples are broader than a scheduled chatbot. OpenAI describes agents that monitor product feedback, prepare tested fixes, revise launch materials when scope changes, update analysis as evidence arrives and maintain proposals as requirements evolve. Reuters reported that the live launch demonstrations also experienced voice-update failures, a useful reminder that capability and operating reliability need separate evidence.
Built-in controls do not replace buyer evidence
OpenAI’s published safeguards include isolated cloud workspaces, read-only tools for proactive research, app permissions, Custom Rules, Activity View and Auto-review before certain consequential actions. OpenAI says some actions need confirmation each time, while password changes and financial transfers require the user to take over. It also says prompt-injection protections reduce risk but do not eliminate it, and that Dots can still make mistakes.
Those controls are important, but a business still owns the workflow design. A vendor safeguard cannot decide which customer record an agent should touch, what evidence is sufficient to change a proposal, how quickly a mistaken edit must be reversed or who is accountable when work crosses departments. Production approval should depend on observed behaviour in your systems, not a feature list.
Run a 30-day authority and recovery test
Choose one reversible workflow with a named owner and a measurable baseline. Keep access narrow, then collect an evidence pack across five gates.
- Authority: list every system, data class and action the agent may read, draft, change or never touch.
- Approval: test whether each high-impact action stops for the right person, recipient, amount and context.
- Evidence: require source links, before-and-after records and a clear reason for every material recommendation or change.
- Recovery: rehearse wrong-recipient, wrong-file, stale-context and prompt-injection scenarios; measure detection, containment and reversal time.
- Shutdown: prove that disabling the agent, disconnecting apps and rotating credentials stops new access without losing the audit trail.
What leaders should approve after the test
Approve expansion only when the workflow beats its baseline without widening authority by accident. Track completion quality, supervision time, blocked actions, incorrect actions, recovery time and exceptions per completed outcome. A fast agent that creates more review work or cannot explain its changes is not cheaper automation.
Version the agent’s rules, connections and acceptance tests together. Any new app, data source, recipient class or write permission should trigger targeted retesting. Keep irreversible actions and sensitive identity changes outside the agent until the evidence supports a deliberate exception. ELYMENT AI can help teams turn agent capability into governed workflows with visible ownership, approvals and proof before scale.
Sources
- OpenAI: Introducing dots (29 September 2026) - Official launch announcement covering Dots capabilities, rollout, connected channels, permissions and enterprise pilots.
- OpenAI: How we build safety, security, and privacy into dots (29 September 2026) - Official explanation of isolation, secure sign-in, proactive research, Custom Rules, Auto-review, approvals and remaining limitations.
- OpenAI Help Center: Dots privacy, security, and safety FAQs (29 September 2026) - Operational guidance on data access, retention, approvals, reversibility, monitoring and prompt-injection protections.
- Reuters: OpenAI takes on Meta with Dots agent in autonomous AI push (29 September 2026) - Independent reporting on the launch, capabilities, safeguards, business positioning and demonstration reliability.
Continue learning
Frequently asked questions
What are OpenAI Dots?
Dots are OpenAI’s always-on agents. OpenAI says they can continue projects between conversations using a cloud computer, connected apps and channels including ChatGPT, Slack and Teams.
Can a Dot take actions without approval?
Some supported actions can proceed within the user’s instructions and Custom Rules. OpenAI says other actions require approval, and certain highly sensitive steps must be completed by the user.
How should a business pilot an always-on agent?
Start with one reversible workflow and test authority, approvals, evidence, recovery and shutdown. Expand access only after the agent meets measurable acceptance criteria.