OpenAI Dots explained: the always-on agent inside ChatGPT
Dots, OpenAI's headline DevDay launch, are agents with their own cloud computer that stay on in ChatGPT, Slack and Teams and keep working between conversations. What they can do, who gets them, and how permissions and approvals work.

On this page
The first thing OpenAI announced at its DevDay keynote on September 29 was Dots. A dot is an agent with its own cloud computer that stays on all day and keeps working on what you gave it after the conversation ends. OpenAI writes the name in lowercase for a single agent, “your dot”, and so does this post.
OpenAI’s one-line pitch is “remarkably capable, always-on agents built to handle everything.” Every, which tested Dots before launch, wrote that its dot had become the main way it used ChatGPT. Here is what they do, who can use them, and what to watch out for.
At a glance
| Item | Details |
|---|---|
| What | A personal agent that stays on, with its own cloud computer and browser |
| Model | GPT-6 Astra |
| Where you talk to it | ChatGPT on desktop, web and mobile; Slack; Teams. Texting is a limited beta for US Pro users |
| Who gets it | Pro and Business Premium. Enterprise, Edu and Healthcare get a beta their admin can turn on |
| Price | Your first dot comes with the plan at no extra cost. Extra dots: price not announced |
| Connections | More than 4,000 apps through plugins |
How it differs from the ChatGPT you know
OpenAI’s help center puts it this way: a dot takes on ongoing responsibility and keeps making progress between conversations. You give it a goal and define what it may do on its own. It works out the next step, brings results back for review, and comes to you for decisions that need your judgment.
It also has its own place to work. Each dot runs on its own cloud computer and browser, so work continues when your laptop is closed, and you can open that computer at any time to see what it is doing. Access to your own computer is optional and starts switched off.
TechCrunch points out that much of this was already possible with Codex and similar agent tools. What Dots adds is the package: those pieces bundled into one agent built to act without being directed at every step.
What you can hand to a dot
OpenAI’s examples:
- An early tester’s dot noticed he had forgotten to invoice a publication, prepared the invoice, and sent it after he approved.
- Inside OpenAI, when a bug report appears in Slack, dots start investigating; when a new design arrives, dots turn it into a working app.
- A dot can run with one project while working on several others, so you keep handing it new tasks without splitting them into separate threads.
Every’s hands-on adds everyday scenes. Its dot filtered incoming Slack requests and emails so they could be triaged without opening the inbox, and while rescheduling a flight it warned that the new time clashed with a Slack meeting request nobody had read yet.
Dots also look for ways to help before you ask, which OpenAI calls proactive research. That background work reads your connected apps with read-only tools and leaves notes. At that stage a dot cannot send messages, change app content, or control a browser or computer; OpenAI says the limit is enforced in code.
Where and how you talk to it
You can message a dot, or call it by voice, in ChatGPT on desktop, web and mobile, and it messages you with progress and questions. It also works in Slack and Teams, carrying the same context across every channel.
A few setup details:
- You create a dot in the ChatGPT desktop app (Windows included) or on desktop web. After that you can talk to it in the mobile app; mobile web is not supported.
- You can name it. The default handle looks like
@yourname-dot. - You can connect a personal email account, but at launch a dot cannot have an email address of its own.
- At launch a dot cannot start a phone call to you.
- Texting is a limited beta for some US Pro users and goes through a third-party provider.
Who gets it, and what it costs
Dots are rolling out to ChatGPT Pro and Business Premium. For Pro, that means markets outside the European Economic Area, Switzerland and the UK. Business Premium covers every region ChatGPT supports. Enterprise, Edu and Healthcare workspaces get a beta that an admin has to switch on; it is off by default. Access can take a few days to reach an account.
On cost:
- Your first dot is included in Pro and Business Premium at no extra cost.
- Conversations with your dot do not count toward ChatGPT usage limits. Tasks it starts in Codex or ChatGPT Work count as usual.
- For the first month, dot usage does not count toward plan allowances; OpenAI will publish per-plan terms after that.
- Adding more dots, or scaling a dot’s speed and monthly workload, is coming “in the future.” No prices yet.
- Dots are not available to users under 18.
Permissions and approvals
This is the part people ask about most for an agent that acts on its own. OpenAI describes several layers.
Custom Rules. For actions such as sharing, buying or accessing something, you pick one of four behaviors: take action without asking, take action if pre-approved, ask before taking action, or hand off to you. “Pre-approved” means you explicitly asked for that action in your prompt.
A separate check before acting. Before a dot sends an email or changes a file, a separate safety system called Auto-review checks the planned step against your instructions, your rules and OpenAI’s safety requirements. For an email it checks the recipient and the message, to catch a wrong address or something you did not mean to share.
Defaults you cannot switch off. For changing a password or moving money between financial accounts, a dot can help with the surrounding work but hands the final step back to you. Permanently deleting data, installing software from an unrecognized source, and granting new security-sensitive access need your confirmation every time. Health information is shared only with a recipient you name.
Sign-ins. On supported sites you type credentials into a secure login form, and the password goes to the browser environment without ever appearing to the model.
Watching and stopping. Activity View in the desktop app shows ongoing work, where you can redirect or stop it. If safety monitoring spots a concern, it pauses the dot’s work and shows you a warning.
Data and memory
A dot uses ChatGPT’s memory and builds memories of its own, including from connected apps. Some limits come with that:
- You cannot yet view or delete individual things a dot remembers. Deleting the dot is the only way to clear them.
- Disconnecting an app does not remove what the dot already learned from it.
- Content in Business, Enterprise and Edu workspaces is not used for training by default. Personal plans follow the “Improve the model for everyone” setting.
- Even with that setting off, the help center says people may review activity in limited cases, such as safety investigations.
Specialist dots for organizations
OpenAI also previewed specialist dots that take on a defined role inside a company. The company gives each one its own identity, credentials and access to the systems it needs. OpenAI says it built on internal trials in procurement, invoice processing and customer support, is starting with focused enterprise pilots, and is working with Microsoft to manage these dots through Agent 365.
What to keep in mind
- Timing. Dots arrived right after OpenAI disclosed a string of agent incidents. The day before the keynote it published an apology after its models accessed Australian government websites, and Sam Altman told CNBC he knew of nothing as serious as the Hugging Face breach disclosed this summer. Engadget reads the heavy emphasis on safety features in that light.
- Early rough edges. In days of testing before launch, Every ran into frequent permission problems and dropped messages, and its dot often could not reach the in-app browser. Its advice: wait a week or two. On stage, a dot named “Dottie” took a long time to answer during the live demo (Engadget).
- Price and terms. Usage terms after the first month and the price of extra dots have not been published.
- Memory control. Because individual memories cannot be deleted, think before connecting sensitive apps.
- Mistakes. OpenAI’s own words: “Dots can still make mistakes, so always review consequential work.”
Every compares Dots with Meta’s Muse, Instinct and Grok Bots, and TechCrunch notes that the cartoon look resembles Muse.
And in endue
endue agents also work while nobody is watching, under slightly different rules:
- Routines run on a schedule whether or not endue is open.
- Channels let people reach an agent from Slack, Discord, KakaoTalk, NaverTalk or WhatsApp, with a policy for who is allowed to call it.
- Approvals stop every action that cannot be undone or reaches someone else, such as sending an email or deleting a file, and that gate cannot be switched off. In an unattended routine run, such an action is refused instead of left waiting.
The two products answer the same question differently. Dots let you pre-approve some actions through rules; endue runs irreversible actions only while a person is there to approve them.
Sources
- OpenAI, Introducing dots (September 29, 2026)
- OpenAI, How we build safety, security, and privacy into dots
- OpenAI, DevDay 2026 Recap
- OpenAI Help Center, Getting started with your dot and Dots privacy, security, and safety FAQs
- OpenAI, How we will do better for Australia (September 28, 2026)
- TechCrunch, OpenAI launches Dots, its bubbly agentic avatar
- Engadget, Dots are OpenAI’s new personal agents and the DevDay live blog
- CNBC, OpenAI DevDay 2026 live updates
- Bloomberg, OpenAI Unveils Always-On AI Agent Dots, New $500 Paid Tier
- Every, Vibe Check: OpenAI DevDay 2026


