In this article
- What can a Dot access?
- How do Custom Rules and Auto-review work?
- Actions OpenAI says always stay sensitive
- How do passwords and sign-in work?
- What does OpenAI retain, and how do I delete it?
- Does OpenAI train on Dots data?
- How do Enterprise admins enable Dots?
- How do I pause, redirect, or stop a Dot?
- Prompt injection and remaining limits
- What to watch next
The short answer
- Each Dot runs in its own sandboxed cloud computer. Your laptop stays disconnected until you grant access in the ChatGPT desktop app.
- Enterprise Dots are a beta that is off by default. A workspace admin must enable them.
- OpenAI says it does not use ChatGPT Business, Enterprise, or Edu content to train models by default, including Dots conversations and work.
- Auto-review checks planned actions such as sending email or changing files against your instructions, Custom Rules, and safety requirements.
- Custom Rules cannot turn off core safety requirements, Auto-review, or proactive-research restrictions.
OpenAI shipped Dots with a dedicated safety post, a help-center FAQ, and admin-off Enterprise access. As of September 29, 2026, the controls below are what those pages describe. OpenAI also writes that Dots can still make mistakes, and that you should review consequential work.
#What can a Dot access?
You choose the apps. Plugin permissions are shared across Dots, ChatGPT, ChatGPT Work, and Codex. Manage them in ChatGPT's Plugins tab. A Dot can use existing connections within the permissions you already granted.
Each Dot has its own cloud computer for browsing, files, and tools. Sandboxing limits what that environment can reach. OpenAI says it isolates users' cloud environments from one another and maintains the Linux OS and Chrome browser. Code runs in an environment separate from the systems that enforce safeguards, so a Dot cannot turn those checks off.
Your laptop starts disconnected. To connect it, use the ChatGPT desktop app on that computer and confirm Allow access. Work on the local machine runs as separate tasks. Confirm Revoke access to stop file access. Camera, microphone, or screen access needs both the computer connection and the matching device permission for the ChatGPT app.
A Dot can review connected information proactively and form memories from it, even without a new question from you. That is by design. Treat plugin connections as standing access.
#How do Custom Rules and Auto-review work?
Dots start with built-in rules for when to act, when to ask, and when to hand a step back. Custom Rules let you tighten or loosen supported actions. On mobile, Customize → Custom rules offers:
- Take action without asking
- Take action if pre-approved
- Ask before taking action
- Hand off to you
"Pre-approved" means you explicitly requested the action in your prompt. OpenAI's examples include never sending emails, or telling a colleague you are away without sharing the personal reason. A Dot can help draft a rule. It needs your approval to change rules.
Custom Rules cannot remove:
- Mandatory confirmations and handoffs (changing a password, transferring money)
- Auto-review
- Proactive-research restrictions
- Core safety refusals, including biological or cybersecurity misuse
Auto-review is a separate system that checks planned steps such as sending email or changing files against your instructions, Custom Rules, and safety requirements. If it allows a step, the Dot runs it. If it blocks a step, it tells the Dot why. The Dot may ask you, try a permitted alternative, hand the step back, or stop. Your approval cannot override core safety requirements. OpenAI says the Auto-review controls sit outside environments Dots can change.
Safety monitoring can pause active work and show a warning if it flags a concern.
#Actions OpenAI says always stay sensitive
Action | What OpenAI documents |
|---|---|
Change a password or transfer money | Dot helps around the task; you complete the sensitive step |
Permanently delete data, install software from an unrecognized source, grant new security-sensitive access | Confirmation each time |
Send a message or share a file | Authorization tied to the information and recipient; health data needs a named recipient |
Purchase with a card saved on a merchant site | Your approval, which may be given in advance when it specifically covers the purchase |
Proactive research | Read-only; cannot send messages, change plugin content, or control a browser or computer |
#How do passwords and sign-in work?
For supported sign-ins, the model pauses while you complete a secure login form. Credentials go to the browser environment. They are not placed in the model's context. Saved-password flows use a dedicated encrypted credential service that supplies the password for sign-in without passing it to the model.
These protections apply to those flows. A secret you paste into a chat, a document, or a plugin message can still be visible to the model. You may need to enter an authentication code or take over for a security check.
#What does OpenAI retain, and how do I delete it?
A Dot retains context from conversations and plugins for as long as the Dot exists. OpenAI says that context does not retain credentials, images, or screenshots. Files in ChatGPT Library, on your computer, or in connected storage follow those locations' retention policies. Content is encrypted in storage and in transit.
Memory is shared with ChatGPT. A Dot can receive ChatGPT memories and recent chat context. Dot conversations can contribute to ChatGPT memory. Turning Memory off in ChatGPT stops new sharing. It does not delete what the Dot already received.
You currently cannot view, delete, or edit individual Dot memories, including details that entered from plugins. To delete the Dot's own context, reset/delete the Dot. The setup guide says Reset deletes its conversations and scheduled tasks; follow the in-product confirmation. Files, Codex threads, and ChatGPT conversations the Dot created remain. ChatGPT memories from other chats remain unless you clear them there.
Disconnecting a plugin stops new access. It does not wipe context already built.
Human review may still occur in limited safety-related cases even when model improvement is off, according to the Dots FAQ.
#Does OpenAI train on Dots data?
Business, Enterprise, and Edu: OpenAI says it does not use your content to train models by default. That includes Dots conversations and work.
Personal ChatGPT plans: the Improve the model for everyone setting controls whether Dots conversations and the work they carry out may be used. OpenAI says this can include actions Dots take, work they delegate, automations you set up, and connected-app data used to inform conversations, after it works to remove personal identifiers.
Proactive research is treated separately. OpenAI says it does not train directly on those background threads or their notes. If a Dot later brings a note into an eligible conversation or task, that brought-in information may be used for training depending on your settings. The leftover background research is not used unless it is also brought in.
You can submit access, correction, or deletion requests through OpenAI's Privacy Portal or dsar@openai.com.
#How do Enterprise admins enable Dots?
As of September 29, 2026:
- Dots are rolling out to Pro users outside the EEA, Switzerland, and the UK.
- Business Premium users can use Dots in all supported ChatGPT regions.
- Enterprise (including Edu and Healthcare in the launch post) is a beta, off by default. A workspace admin enables it.
- Access may take several days to reach an account.
- Users must be 18 or older.
- Create the Dot in the ChatGPT desktop app or desktop web. You cannot create one on mobile. Dots are not supported on mobile web.
OpenAI’s admin guide documents Workspace settings > Permissions & roles, then Use dots (Beta) under workspace capabilities or a custom role. Slack and local computer access have separate permissions. Related plugin and cloud-computer controls also apply.
Specialist dots are a separate enterprise preview: a company-provisioned identity, credentials, and access to systems of record, with early internal testing in procurement, invoice processing, email marketing, customer support, and commercial contracting. OpenAI says it is starting with focused pilots and is working with Microsoft to integrate specialist dots with Agent 365 governance. That is not the same as turning on a member's personal Dot.
The Help Center describes a limited US Pro texting beta, unavailable in Business or Enterprise workspaces. The launch post and messaging guide still say texting is coming soon; availability depends on your account.
#How do I pause, redirect, or stop a Dot?
Activity View in the desktop app shows ongoing and delegated tasks. Use Scheduled to review recurring work. You can add context, correct a misunderstanding, change direction, or ask the Dot to stop.
To pause the current main task, open the profile menu and select Pause. Stop delegated tasks in Activity and cancel recurring runs in Scheduled separately.
The Help Center calls deletion Reset in the profile menu; ChatGPT Learn calls it Delete. Read the confirmation and save needed results first. After deletion, create a new Dot on desktop.
Whether a completed action can be reversed depends on the app. OpenAI says a Dot may be able to undo some document edits or recall an email. Some actions cannot be undone.
#Prompt injection and remaining limits
OpenAI names prompt injection as a live risk: a webpage, email, or document can hide instructions that try to redirect the Dot or leak data. Mitigations listed are model training, tool restrictions, pre-action checks, monitoring, and user confirmation. OpenAI says these reduce the risk. They do not eliminate it.
The GPT-6 Astra system card is linked from the Dots safety post for evaluations and remaining limitations. Read that card before you connect mail, calendar, or a production repo.
#What to watch next
Watch for post-launch usage terms, further specialist-dot governance details, and changes to individual memory controls. As of September 29, 2026, the checked documentation requires deleting the Dot to clear its own context; separately stored artifacts and shared ChatGPT memories have separate controls.
Frequently asked questions
Do Dots train OpenAI's models on my work chat?
For ChatGPT Business, Enterprise, and Edu, OpenAI says it does not use your content to train models by default. On personal plans, the 'Improve the model for everyone' setting controls whether Dots conversations and work may be used, after OpenAI says it works to remove personal identifiers.
Can an Enterprise admin leave Dots off?
Yes. OpenAI says Enterprise access is a beta and is initially turned off by default. Workspace admins enable it. Edu and Healthcare are grouped with that Enterprise beta in the Dots launch post.
Does disconnecting a plugin erase what a Dot already learned?
No. Disconnecting stops new sharing. Information already in the Dot's context remains. OpenAI says you delete that context by deleting the Dot.
Can a Dot see my passwords?
For supported sign-ins, OpenAI says the model is paused while you complete a secure login form that sends credentials to the browser environment without exposing them to the model. Secrets pasted in a chat or document can still be visible to the model.
What can I stop a Dot from doing?
Custom Rules can require approval, block actions such as sending email, or allow pre-approved actions. Pause stops the main task; stop delegated and recurring work separately. Custom Rules cannot waive password-change or money-transfer handoffs, Auto-review, or core safety refusals.
Are Dots available to people under 18?
No. OpenAI's Dots privacy FAQ says Dots are not yet available to users under 18. Release notes say rollout is to eligible Pro and Business Premium users aged 18 and older.
Sources
Every factual claim in this article traces back to one of these.
One email when Dots change.
Launches, rollout changes and the guides worth reading. At most once a week, and you can leave with one click.



